PT-2020-7484 · Drupal · Drupal Restws Module

Published

2020-02-11

·

Updated

2023-02-13

·

CVE-2013-4225

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Drupal restws module versions 7.x-1.x before 7.x-1.4 Drupal restws module versions 7.x-2.x before 7.x-2.1
Description: The issue allows remote authenticated users with certain permissions, such as access resource node and create page content, to potentially conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field, due to improper restriction of access to entity write operations.
Recommendations: For Drupal restws module version 7.x-1.x, update to version 7.x-1.4 or later. For Drupal restws module version 7.x-2.x, update to version 7.x-2.1 or later.

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2013-4225

Affected Products

Drupal Restws Module