CVE-2013-4225

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/02/2020
Last modified:
13/02/2023

Description

The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:restful_web_services_project:restful_web_services:*:*:*:*:*:drupal:*:* 7.x-1.0 (including) 7.x-1.4 (excluding)
cpe:2.3:a:restful_web_services_project:restful_web_services:*:*:*:*:*:drupal:*:* 7.x-2.0 (including) 7.x-2.1 (excluding)
cpe:2.3:a:restful_web_services_project:restful_web_services:7.x-2.x:dev:*:*:*:drupal:*:*