AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2012-1650

MEDIUM · CVSS 6 EPSS 1.20%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-08-28 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-1650
Severity
MEDIUM
CVSS
6
EPSS
1.20%

Original Filing — NVD Description

The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when building archives, which allows remote authenticated users with access content permission to bypass intended access restrictions.