Back to search
CVE-2013-0259
Published: Mar 27, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
57642
vdb-entry
x_refsource_BID
http://drupal.org/node/1897016
x_refsource_CONFIRM
[oss-security] 20130204 Re: CVE request for Drupal contributed modules
mailing-list
x_refsource_MLIST
http://drupalcode.org/project/boxes.git/commitdiff/456ff8e
x_refsource_CONFIRM
http://drupal.org/node/1903300
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now