CVE-2013-2129: XSS
Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.19 for Drupal allows remote authenticated users with the "edit own webform content" or "edit all webform content" permissions to inject arbitrary web script or HTML via a component label.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2129?
CVE-2013-2129 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-2129?
To fix CVE-2013-2129, update the Webform module to version 6.x-3.19 or later.
Who is affected by CVE-2013-2129?
Authenticated users with 'edit own webform content' or 'edit all webform content' permissions are affected by CVE-2013-2129.
What types of attacks can be carried out due to CVE-2013-2129?
CVE-2013-2129 allows for arbitrary web script or HTML injection, which can lead to session hijacking or content spoofing.
What versions of the Webform module are vulnerable to CVE-2013-2129?
The Webform module versions 6.x-3.0 to 6.x-3.18 are vulnerable to CVE-2013-2129.