LOW
Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name
Published Mar 19, 2013
2.1
LOWCVSS 2.0
EPSS 1.04%
Description
Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.
Affected products
No data.
Configuration 1
AND
OR
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.0
- 6.x-1.1
- 6.x-1.2
- 6.x-1.3
- 6.x-1.x
Configuration 2
AND
OR
- 7.x-1.0
- 7.x-1.0
- 7.x-1.0
- 7.x-1.0
- 7.x-1.x
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9 x_refsource_CONFIRM
- http://drupalcode.org/project/user_relationships.git/commitdiff/b9a4739 x_refsource_CONFIRM
- http://www.openwall.com/lists/oss-security/2013/01/25/4 mailing-listx_refsource_MLIST
- https://drupal.org/node/1896272 x_refsource_CONFIRMPatch
- https://drupal.org/node/1896276 x_refsource_CONFIRMPatch
- https://drupal.org/node/1896720 x_refsource_MISCPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0259 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://drupalcode.org/project/user_relationships.git/commitdiff/17e94b9 | x_refsource_CONFIRM | |
| http://drupalcode.org/project/user_relationships.git/commitdiff/b9a4739 | x_refsource_CONFIRM | |
| http://www.openwall.com/lists/oss-security/2013/01/25/4 | mailing-listx_refsource_MLIST | |
| https://drupal.org/node/1896272 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/1896276 | x_refsource_CONFIRMPatch | |
| https://drupal.org/node/1896720 | x_refsource_MISCPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-0259 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 19, 2013
Updated Sep 16, 2024
Reserved Dec 6, 2012
Link CVE-2013-0225
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data