CVE-2012-2724: Md-Systems Simplenews

Medium severity, CVSS 5.3. EPSS: 2.5% chance of exploitation in the next 30 days.

The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.

Affected products

  • Md-Systems Simplenews: version 6.x-1.0 only; version 6.x-1.1 only; version 6.x-1.2 only; version 6.x-1.3 only; version 6.x-2.0 only; version 6.x-2.x only; …

Published 2020-01-09. Last modified 2026-06-16.