CVE-2013-4447: XSS
Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4447?
CVE-2013-4447 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-4447?
To fix CVE-2013-4447, upgrade the Simplenews module to version 6.x-1.5 or later for Drupal 6.x, or to version 7.x-1.1 or later for Drupal 7.x.
Who is affected by CVE-2013-4447?
CVE-2013-4447 affects users of the Simplenews module for Drupal versions 6.x-1.0 through 6.x-1.4 and 7.x-1.0 through 7.x-1.0 beta releases.
What type of vulnerability is CVE-2013-4447?
CVE-2013-4447 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Can CVE-2013-4447 lead to serious security issues?
Yes, CVE-2013-4447 can lead to security issues such as unauthorized access or data manipulation by exploiting the XSS vulnerability.