Vulnerability Description
Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to options.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Feed Element Mapper Project | Feed Element Mapper | - |
Related Weaknesses (CWE)
References
- http://seclists.org/oss-sec/2013/q4/210
- https://drupal.org/node/2124279Vendor Advisory
- http://seclists.org/oss-sec/2013/q4/210
- https://drupal.org/node/2124279Vendor Advisory
FAQ
What is CVE-2013-4503?
CVE-2013-4503 is a vulnerability with a CVSS score of 2.1 (LOW). Cross-site scripting (XSS) vulnerability in the Feed Element Mapper module for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML...
How severe is CVE-2013-4503?
CVE-2013-4503 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4503?
Check the references section above for vendor advisories and patch information. Affected products include: Feed Element Mapper Project Feed Element Mapper.