CVE-2013-1905
Description
Reflected XSS in Zero Point theme for Drupal 7.x before 7.x-1.9 allows remote attackers to inject arbitrary web script via URLs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in Zero Point theme for Drupal 7.x before 7.x-1.9 allows remote attackers to inject arbitrary web script via URLs.
Vulnerability
The Zero Point theme for Drupal 7.x versions prior to 7.x-1.9 does not escape user-supplied text in URLs, leading to a reflected cross-site scripting (XSS) vulnerability. [2][3]
Exploitation
An attacker can craft a malicious URL containing arbitrary script or HTML. When a victim visits the crafted URL, the script executes in the context of the victim's browser. No authentication or special privileges are required; the attack is remote. [2][3]
Impact
Successful exploitation allows the attacker to inject arbitrary web script or HTML, potentially leading to session hijacking, defacement, or theft of sensitive data. The vulnerability is rated moderately critical. [2][3]
Mitigation
Upgrade to zeropoint 7.x-1.9, released on 2013-March-27. [3][4] No workarounds are provided. Drupal core is not affected. [3]
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
11cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.0:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.1:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.2:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.3:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.4:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.5:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.6:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.7:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.8:*:*:*:*:*:*:*
- cpe:2.3:a:catalin_florian_radut:zeropoint:7.x-1.x:dev:*:*:*:*:*:*
- Range: < 7.x-1.9
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
8- drupal.org/node/1954588nvdPatchVendor Advisory
- drupal.org/node/1953840nvdPatch
- secunia.com/advisories/52775nvdVendor Advisory
- osvdb.org/91745nvd
- packetstormsecurity.com/files/120985/Drupal-Zero-Point-7.x-Cross-Site-Scripting.htmlnvd
- seclists.org/fulldisclosure/2013/Mar/241nvd
- www.securityfocus.com/bid/58758nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/83137nvd
News mentions
0No linked articles in our index yet.