CVE-2013-4230
Last modified
CVE-2013-4230 is a vulnerability of currently unknown severity. The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access to webform submissions, which allows remote authenticated users with the "Who can read data submitted to this webform" permission to delete arbitrary submissions via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Monster Menus Project | Monster Menus | 6.x-6.19 | — |
| Monster Menus Project | Monster Menus | 6.x-6.22 | — |
| Monster Menus Project | Monster Menus | 6.x-6.23 | — |
| Monster Menus Project | Monster Menus | 6.x-6.24 | — |
| Monster Menus Project | Monster Menus | 6.x-6.25 | — |
| Monster Menus Project | Monster Menus | 6.x-6.26 | — |
| Monster Menus Project | Monster Menus | 6.x-6.27 | — |
| Monster Menus Project | Monster Menus | 6.x-6.29 | — |
| Monster Menus Project | Monster Menus | 6.x-6.30 | — |
| Monster Menus Project | Monster Menus | 6.x-6.31 | — |
| Monster Menus Project | Monster Menus | 6.x-6.32 | — |
| Monster Menus Project | Monster Menus | 6.x-6.33 | — |
| Monster Menus Project | Monster Menus | 6.x-6.34 | — |
| Monster Menus Project | Monster Menus | 6.x-6.35 | — |
| Monster Menus Project | Monster Menus | 6.x-6.36 | — |
| Monster Menus Project | Monster Menus | 6.x-6.37 | — |
| Monster Menus Project | Monster Menus | 6.x-6.38 | — |
| Monster Menus Project | Monster Menus | 6.x-6.41 | — |
| Monster Menus Project | Monster Menus | 6.x-6.42 | — |
| Monster Menus Project | Monster Menus | 6.x-6.43 | — |
| Monster Menus Project | Monster Menus | 6.x-6.44 | — |
| Monster Menus Project | Monster Menus | 6.x-6.48 | — |
| Monster Menus Project | Monster Menus | 6.x-6.53 | — |
| Monster Menus Project | Monster Menus | 6.x-6.56 | — |
| Monster Menus Project | Monster Menus | 6.x-6.57 | — |
| Monster Menus Project | Monster Menus | 6.x-6.59 | — |
| Monster Menus Project | Monster Menus | 6.x-6.60 | — |
| Monster Menus Project | Monster Menus | 7.x-1.0 | — |
| Monster Menus Project | Monster Menus | 7.x-1.1 | — |
| Monster Menus Project | Monster Menus | 7.x-1.2 | — |
| Monster Menus Project | Monster Menus | 7.x-1.3 | — |
| Monster Menus Project | Monster Menus | 7.x-1.4 | — |
| Monster Menus Project | Monster Menus | 7.x-1.5 | — |
| Monster Menus Project | Monster Menus | 7.x-1.6 | — |
| Monster Menus Project | Monster Menus | 7.x-1.7 | — |
| Monster Menus Project | Monster Menus | 7.x-1.8 | — |
| Monster Menus Project | Monster Menus | 7.x-1.9 | — |
| Monster Menus Project | Monster Menus | 7.x-1.10 | — |
| Monster Menus Project | Monster Menus | 7.x-1.11 | — |
| Monster Menus Project | Monster Menus | 7.x-1.12 | — |
| Monster Menus Project | Monster Menus | 7.x-1.x | Dev |
References
- http://secunia.com/advisories/54391Vendor Advisory
- https://drupal.org/node/2059823Vendor Advisory
- http://secunia.com/advisories/54391Vendor Advisory
- https://drupal.org/node/2059823Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4230?
How severe is CVE-2013-4230?
How do I fix CVE-2013-4230?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-4224Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2013-4225The RESTful Web Services (restws) module 7.x-1.x before 7.x-…8.8
- CVE-2013-4226The Authenticated User Page Caching (Authcache) module 7.x-1…6.5
- CVE-2013-4227Cross-site request forgery (CSRF) vulnerability in the perso…8.8
- CVE-2013-4228The OG access fields (visibility fields) implementation in O…4.3
- CVE-2013-4229Cross-site scripting (XSS) vulnerability in the Monster Menu…
- CVE-2013-4231Multiple buffer overflows in libtiff before 4.0.3 allow remo…
- CVE-2013-4232Use-after-free vulnerability in the t2p_readwrite_pdf_image …
- CVE-2013-4233Integer overflow in the abc_set_parts function in load_abc.c…
- CVE-2013-4234Multiple heap-based buffer overflows in the (1) abc_MIDI_dru…
- CVE-2013-4235shadow: TOCTOU (time-of-check time-of-use) race condition wh…4.7
- CVE-2013-4236VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows p…
Are you affected by CVE-2013-4230?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
