CVE-2013-1393: XSS
Cross-site scripting (XSS) vulnerability in the CurvyCorners module 6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with the "administer curvycorners" permission to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1393?
CVE-2013-1393 has a medium severity rating due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2013-1393?
To fix CVE-2013-1393, update the CurvyCorners module to the latest version that addresses this vulnerability.
Who is affected by CVE-2013-1393?
CVE-2013-1393 affects remote authenticated users with the 'administer curvycorners' permission on Drupal installations running vulnerable versions of the CurvyCorners module.
What version of CurvyCorners is vulnerable to CVE-2013-1393?
Versions 6.x-1.x and 7.x-1.x of the CurvyCorners module are vulnerable to CVE-2013-1393.
Can CVE-2013-1393 lead to data exposure?
Yes, CVE-2013-1393 can potentially allow attackers to inject malicious scripts, leading to data exposure or session hijacking.