CVE-2013-4225
Summary
| CVE | CVE-2013-4225 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-11 21:15:00 UTC |
| Updated | 2023-02-13 00:28:00 UTC |
| Description | The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field. |
Risk And Classification
Problem Types: CWE-79 | CWE-94
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Restful Web Services Project | Restful Web Services | All | All | All | All |
| Application | Restful Web Services Project | Restful Web Services | 7.x-2.x | dev | All | All |
| Application | Restful Web Services Project | Restful Web Services | All | All | All | All |
| Application | Restful Web Services Project | Restful Web Services | 7.x-2.x | dev | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SA-CONTRIB-2013-062 - RESTful Web Services (RESTWS) - Access Bypass | drupal.org | MISC | drupal.org | Patch, Vendor Advisory |
| restws 7.x-2.1 | drupal.org | MISC | drupal.org | Release Notes, Vendor Advisory |
| CVE-2013-4225 - Red Hat Customer Portal | MISC | access.redhat.com | |
| Red Hat Customer Portal - Access to 24x7 support and knowledge | MISC | access.redhat.com | |
| 997639 – (CVE-2013-4225) CVE-2013-4225 Katello: proxied Candlepin calls authorization bypass | MISC | bugzilla.redhat.com | |
| oss-security - Re: CVE request for Drupal contributed modules | MISC | www.openwall.com | Mailing List, Third Party Advisory |
| restws 7.x-1.4 | drupal.org | MISC | drupal.org | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.