The Simplenews Scheduler module 6.x-2.x before 6.x-2.4...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Dec 3, 2012
Published to the GitHub Advisory Database
May 17, 2022
Last updated
Jan 28, 2023
The Simplenews Scheduler module 6.x-2.x before 6.x-2.4 for Drupal allows remote authenticated users with the "send scheduled newsletters" permission to inject arbitrary PHP code into the scheduling form, which is later executed by cron.
References