VULNERABILITY INTELLIGENCE

CVE-2011-0899

CVSS score5 MEDIUM
EPSS probability0.90%
CISA KEVNot currently listed
Published2011-02-07
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:P/I:N/A:N

Description

The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user.

Primary references