CVE-2008-10004 is a critical SQL injection vulnerability affecting the Email Registration 5.x-2.1 module for Drupal, specifically within the email_registration_user function. This flaw allows a remote attacker to manipulate the 'namenew' argument to execute arbitrary SQL commands. With a CVSS score of 9.8, it poses a severe risk, enabling full compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, upgrading to version 6.x-1.0 or applying patch 126c141b7db038c778a2dc931d38766aad8d1112 is strongly recommended to mitigate this high-risk vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.x-2.1CPE matchmatch criteria | cpe:2.3:a:email_registration_project:email_registration:5.x-2.1:*:*:*:*:drupal:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.