Unrated severityNVD Advisory· Published Jul 29, 2013· Updated Apr 29, 2026
CVE-2013-4140
CVE-2013-4140
Description
Cross-site scripting (XSS) vulnerability in the TinyBox (Simple Splash) module before 7.x-2.2 for Drupal allows remote authenticated users with the "administer tinybox" permission to inject arbitrary web script or HTML via unspecified vectors.
Affected products
10cpe:2.3:a:drupalisme:tinybox:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:drupalisme:tinybox:*:*:*:*:*:*:*:*range: <=7.x-2.1
- cpe:2.3:a:drupalisme:tinybox:7.x-1.0:*:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-1.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-1.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-1.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-1.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-1.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-1.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-1.1:*:*:*:*:*:*:*
- cpe:2.3:a:drupalisme:tinybox:7.x-2.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- drupal.org/node/2031575nvdPatch
- drupal.org/node/2038807nvdPatchVendor Advisory
- secunia.com/advisories/54091nvdVendor Advisory
- osvdb.org/95153nvd
- seclists.org/fulldisclosure/2013/Jul/86nvd
- www.openwall.com/lists/oss-security/2013/07/17/1nvd
- www.securityfocus.com/bid/61078nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/85600nvd
News mentions
0No linked articles in our index yet.