Information disclosure in SMTP Authentication Support module for Drupal



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID N/A
CWE-ID CWE-200
Exploitation vector Network
Public exploit N/A
Vulnerable software
SMTP Authentication Support
Web applications / Modules and components for CMS

Vendor Chuva Inc.

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU7260

Risk: Low

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: N/A

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

Exploit availability: No

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability resides within the SMTP Authentication Support module for Drupal, when configured to run in debug mode. The modules logs sensitive information, which can be accessible by remote unauthenticated users.

Mitigation

Update to version 7.x-1.7 or 8.x-1.0-beta3.

Vulnerable software versions

SMTP Authentication Support: 7.x-1.0 - 8.x-1.0-beta2

CPE2.3 External links

https://www.drupal.org/node/2890357


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###