CVE-2012-2702: Tony Freixas Ubercart Product Keys

Medium severity, CVSS 5.0. EPSS: 2.6% chance of exploitation in the next 30 days.

The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to read all unassigned product keys via certain conditions related to the uid.

Affected products

Published 2012-06-27. Last modified 2026-06-16.