CVE-2013-4225
Last modified
CVE-2013-4225 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.. EPSS estimates a 2.00% chance of exploitation in the next 30 days.
Description
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Restful Web Services Project | Restful Web Services | >= 7.x-1.0, < 7.x-1.4 | — |
| Restful Web Services Project | Restful Web Services | >= 7.x-2.0, < 7.x-2.1 | — |
| Restful Web Services Project | Restful Web Services | 7.x-2.x | Dev |
References
- http://www.openwall.com/lists/oss-security/2013/08/10/1Mailing List, Third Party Advisory
- https://drupal.org/node/2059591Release Notes, Vendor Advisory
- https://drupal.org/node/2059593Release Notes, Vendor Advisory
- https://drupal.org/node/2059603Patch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2013/08/10/1Mailing List, Third Party Advisory
- https://drupal.org/node/2059591Release Notes, Vendor Advisory
- https://drupal.org/node/2059593Release Notes, Vendor Advisory
- https://drupal.org/node/2059603Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4225?
How severe is CVE-2013-4225?
How do I fix CVE-2013-4225?
Are you affected by CVE-2013-4225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
