Description
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-4129 | The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field. |
References
History
Mon, 23 Dec 2024 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Redhat satellite Capsule
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:38:01.575Z
Reserved: 2013-06-12T00:00:00.000Z
Link: CVE-2013-4225
No data.
Status : Modified
Published: 2020-02-11T21:15:10.830
Modified: 2024-11-21T01:55:09.930
Link: CVE-2013-4225
OpenCVE Enrichment
No data.
EUVD