QID 154096
Date Published: 2021-07-01
QID 154096: Open Redirect Vulnerability in Drupal Core
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Core 7.x and prior versions then Drupal 7.70
Open redirects or otherwise unvalidated redirects are often used as part of a social engineering or phishing attack because the initial malicious link sent to a victim can use a trusted, legitimate web site's URL to redirect to a link on a malicious web server.
Solution
Customers are advised to upgrade to Drupal 7.70 or later versions to remediate these vulnerabilities.
Vendor References
- SA-CORE-2020-003 -
www.drupal.org/sa-core-2020-003
CVEs related to QID 154096
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Drupal 7.70 |
|