CVE-2013-6387: XSS
Published Dec 24, 2013
·Updated
Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.
Affected Software
40 affected components
Drupal Drupal=7.0
Drupal Drupal=7.0-alpha1
Drupal Drupal=7.0-alpha2
Drupal Drupal=7.0-alpha3
Drupal Drupal=7.0-alpha4
Drupal Drupal=7.0-alpha5
Drupal Drupal=7.0-alpha6
Drupal Drupal=7.0-alpha7
Drupal Drupal=7.0-beta1
Drupal Drupal=7.0-beta2
Drupal Drupal=7.0-beta3
Drupal Drupal=7.0-dev
Drupal Drupal=7.0-rc1
Drupal Drupal=7.0-rc2
Drupal Drupal=7.0-rc3
Drupal Drupal=7.0-rc4
Drupal Drupal=7.1
Drupal Drupal=7.2
Drupal Drupal=7.3
Drupal Drupal=7.4
Drupal Drupal=7.5
Drupal Drupal=7.6
Drupal Drupal=7.7
Drupal Drupal=7.8
Drupal Drupal=7.9
Drupal Drupal=7.10
Drupal Drupal=7.11
Drupal Drupal=7.12
Drupal Drupal=7.13
Drupal Drupal=7.14
Drupal Drupal=7.15
Drupal Drupal=7.16
Drupal Drupal=7.17
Drupal Drupal=7.18
Drupal Drupal=7.19
Drupal Drupal=7.20
Drupal Drupal=7.21
Drupal Drupal=7.22
Drupal Drupal=7.23
Drupal Drupal=7.x-dev
Remediation
Patch Available
Event History
Dec 24, 2013
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6387?
CVE-2013-6387 has been rated as a medium severity vulnerability due to its potential impact on website security.
2
How do I fix CVE-2013-6387?
To fix CVE-2013-6387, upgrade your Drupal installation to version 7.24 or later.
3
Who is affected by CVE-2013-6387?
Anyone using Drupal 7.x versions prior to 7.24, particularly with the Image module enabled, is affected by CVE-2013-6387.
4
What kind of attack can be executed using CVE-2013-6387?
CVE-2013-6387 allows attackers to perform cross-site scripting (XSS) attacks, potentially injecting arbitrary scripts or HTML.
5
Are authenticated users the only ones who can exploit CVE-2013-6387?
Yes, only remote authenticated users with specific permissions can exploit CVE-2013-6387.