VendorsRESTful Web Services projectrestful_web_servicesany version
Vulnerabilities

RESTful Web Services project RESTful Web Services any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2013-4225
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
Published 2020-02-11 · Modified
8.8EPSS 0.021
CVE-2024-13255
RESTful Web Services - Critical - Access bypass - SA-CONTRIB-2024-019
Published 2025-01-09 · Analyzed
7.5EPSS 0.005
CVE-2013-0205
Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
Published 2013-03-19 · Modified
6.8EPSS 0.007