CVE Database
/

CVE-2013-4225

Back to search

CVE-2013-4225

Published: Feb 11, 2020

Modified: Aug 6, 2024

PUBLISHED

Description

The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.

VendorProductVersions

RESTful Web Services

RESTful Web Services

affected
7.x-1.x before 7.x-1.4
affected
7.x-2.x before 7.x-2.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now