CVE-2013-0259
Boxes - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.
References (5)
Scores
EPSS
0.0018
EPSS Percentile
38.7%
Details
CWE
CWE-79
Status
published
Products (11)
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
boxes_project/boxes
... and 1 more
Published
Mar 27, 2013
Tracked Since
Feb 18, 2026