Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6932

Опубликовано: 01 мар. 2018
Источник: nvd
CVSS3: 4.7
CVSS2: 5.8
EPSS Низкий

Описание

Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:*
Версия от 7.0 (включая) до 7.57 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00383
Низкий

4.7 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 7 лет назад

Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.

CVSS3: 4.7
debian
больше 7 лет назад

Drupal core 7.x versions before 7.57 has an external link injection vu ...

CVSS3: 4.7
github
около 3 лет назад

Drupal external link injection vulnerability

EPSS

Процентиль: 59%
0.00383
Низкий

4.7 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601