MEDIUM · 4.3

CVE-2013-4594

The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submi...

Vulnerability Description

The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Payment For Webform ProjectPayment For Webform7.x-1.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-4594?

CVE-2013-4594 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submi...

How severe is CVE-2013-4594?

CVE-2013-4594 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4594?

Check the references section above for vendor advisories and patch information. Affected products include: Payment For Webform Project Payment For Webform.