Описание
Drupal core Open Redirect vulnerability
Drupal 7 has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL.
The vulnerability is caused by insufficient validation of the destination query parameter in the drupal_goto() function.
Other versions of Drupal core are not vulnerable.
Пакеты
Наименование
drupal/core
composer
Затронутые версииВерсия исправления
>= 7.0.0, < 7.70
7.70
4.3 Medium
CVSS3
Дефекты
CWE-601
4.3 Medium
CVSS3
Дефекты
CWE-601