HIGH🇵🇱 Wersja polska

CVE-2013-4225

CVSS 8.8v3.1pub. 2020-02-11upd. 2024-11-21

The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Restful Web Services Project Restful Web Services

    APP
    Restful Web Services Project
    7.x-2.x7.x-1.0 – 7.x-1.4 (excl.)7.x-2.0 – 7.x-2.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2024-13255HIGH7.5same product

Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows For...

CVE-2015-4345MEDIUM5.0same product

The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7...

CVE-2013-1946MEDIUM4.3same product

The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, ...

CVE-2013-0205MEDIUM6.8same product

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x...

CVE-2012-5556MEDIUM6.8same product

Multiple cross-site request forgery (CSRF) vulnerabilities in the RESTful Web Services (RESTWS) module 7.x-1.x...