CVE-2013-4225
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
El módulo RESTful Web Services (restws) versiones 7.x-1.x anteriores a 7.x-1.4 y versiones 7.x-2.x anteriores a 7.x-2.1 para Drupal, no restringe apropiadamente el acceso a las operaciones de escritura de entidades, lo que facilita a usuarios autenticados remotos con los permisos de "access resource node" y "create page content" (o equivalentes) conducir un ataque de tipo cross-site scripting (XSS) o ejecutar código PHP arbitrario por medio de un campo de texto diseñado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-06-12 CVE Reserved
- 2020-02-11 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2013/08/10/1 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://drupal.org/node/2059603 | 2023-02-13 |
URL | Date | SRC |
---|---|---|
https://drupal.org/node/2059591 | 2023-02-13 | |
https://drupal.org/node/2059593 | 2023-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Restful Web Services Project Search vendor "Restful Web Services Project" | Restful Web Services Search vendor "Restful Web Services Project" for product "Restful Web Services" | >= 7.x-1.0 < 7.x-1.4 Search vendor "Restful Web Services Project" for product "Restful Web Services" and version " >= 7.x-1.0 < 7.x-1.4" | drupal |
Affected
| ||||||
Restful Web Services Project Search vendor "Restful Web Services Project" | Restful Web Services Search vendor "Restful Web Services Project" for product "Restful Web Services" | >= 7.x-2.0 < 7.x-2.1 Search vendor "Restful Web Services Project" for product "Restful Web Services" and version " >= 7.x-2.0 < 7.x-2.1" | drupal |
Affected
| ||||||
Restful Web Services Project Search vendor "Restful Web Services Project" | Restful Web Services Search vendor "Restful Web Services Project" for product "Restful Web Services" | 7.x-2.x Search vendor "Restful Web Services Project" for product "Restful Web Services" and version "7.x-2.x" | dev, drupal |
Affected
|