Services Project maintains a narrowly scoped services-focused application whose vulnerability footprint centers on web-application input handling and access-control weaknesses, including cross-site request forgery, improper access control, cross-site scripting, and input-validation flaws. These are characteristic concerns for web-facing applications where request forgery, injection, and authorization gaps recur across the product line. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Services Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9152HIGH The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote | Dec 1, 2014 | 7.5 | 20 | NO | NO |
CVE-2014-9151HIGH The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via | Dec 1, 2014 | 7.5 | 19 | NO | NO |
CVE-2013-2158MEDIUM Cross-site request forgery (CSRF) vulnerability in the Services module 6.x-3.x and 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to hijack the authentication of unspeci | Jul 1, 2013 | 6.8 | 18 | NO | NO |
CVE-2015-4393MEDIUM The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to | Jun 15, 2015 | 6.0 | 17 | NO | NO |
CVE-2015-4394MEDIUM The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private field information via unspecified | Jun 15, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-9153MEDIUM Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the | Dec 1, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Services Project.
Media articles that mention a CVE ID that affects a product developed by Services Project — matched by CVE ID, not by vendor name.