Lucene search

K
cve[email protected]CVE-2013-0205
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2013-0205

2022-10-0316:15:04
CWE-352
web.nvd.nist.gov
17
cve-2013-0205
csrf
vulnerability
drupal
restful web services
restws
nvd
security

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.8%

Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

Affected configurations

NVD
Node
restful_web_services_projectrestful_web_servicesRange7.x-1.07.x-1.2drupal
OR
restful_web_services_projectrestful_web_servicesMatch7.x-2.0-drupal
OR
restful_web_services_projectrestful_web_servicesMatch7.x-2.0alpha1drupal
OR
restful_web_services_projectrestful_web_servicesMatch7.x-2.0alpha2drupal
OR
restful_web_services_projectrestful_web_servicesMatch7.x-2.0alpha3drupal
AND
drupaldrupalRange7.07.82

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

46.8%

Related for CVE-2013-0205