AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2012-5554

MEDIUM · CVSS 5 EPSS 1.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-12-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2012-5554
Severity
MEDIUM
CVSS
5
EPSS
1.37%

Original NVD Description

The default configuration for the Webform CiviCRM Integration module 7.x-3.x before 7.x-3.2 has "Enforce Permissions" disabled, which allows remote attackers to obtain contact information by reading webforms.