CVE-2013-4225

The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
References
Link Resource
https://drupal.org/node/2059603 Patch Vendor Advisory
https://drupal.org/node/2059591 Release Notes Vendor Advisory
http://www.openwall.com/lists/oss-security/2013/08/10/1 Mailing List Third Party Advisory
https://drupal.org/node/2059593 Release Notes Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:restful_web_services_project:restful_web_services:*:*:*:*:*:drupal:*:*
cpe:2.3:a:restful_web_services_project:restful_web_services:*:*:*:*:*:drupal:*:*
cpe:2.3:a:restful_web_services_project:restful_web_services:7.x-2.x:dev:*:*:*:drupal:*:*

Information

Published : 2020-02-11 13:15

Updated : 2023-02-12 16:28


NVD link : CVE-2013-4225

Mitre link : CVE-2013-4225


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')

Advertisement

dedicated server usa

Products Affected

restful_web_services_project

  • restful_web_services