First published: Thu Jun 20 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the CurvyCorners module 6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with the "administer curvycorners" permission to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Curvycorners Curvycorners | =6.x-1.0 | |
Curvycorners Curvycorners | =7.x-1.0 | |
Drupal Drupal |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1393 has a medium severity rating due to the potential for cross-site scripting (XSS) attacks.
To fix CVE-2013-1393, update the CurvyCorners module to the latest version that addresses this vulnerability.
CVE-2013-1393 affects remote authenticated users with the 'administer curvycorners' permission on Drupal installations running vulnerable versions of the CurvyCorners module.
Versions 6.x-1.x and 7.x-1.x of the CurvyCorners module are vulnerable to CVE-2013-1393.
Yes, CVE-2013-1393 can potentially allow attackers to inject malicious scripts, leading to data exposure or session hijacking.