CVE-2019-25012 describes an information disclosure vulnerability in the Webform Report project for Drupal (version 7.x-1.x-dev). Attackers can remotely view webform submissions by accessing the /rss.xml page. This vulnerability has a CVSSv3.1 score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity and high confidentiality impact, requiring no user interaction or privileges. While no public exploit code or active exploitation has been observed, and community discussion is minimal, organizations using the affected Drupal module should be aware of this potential data exposure risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.x-1.x-devCPE matchmatch criteria | cpe:2.3:a:webform_report_project:webform_report:7.x-1.x-dev:*:*:*:*:drupal:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.