PT-2017-7300 · Drupal · Jquery Update+2

Pere Orga

+1

·

Publicado

2015-11-04

·

Atualizado

2017-11-08

·

CVE-2015-7943

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal versions prior to 7.41 jQuery Update module versions prior to 7.x-2.7 for Drupal LABjs module versions prior to 7.x-1.8 for Drupal
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This is due to an incomplete fix for a previous issue.
Recommendations For Drupal versions prior to 7.41, update to version 7.41 or later. For jQuery Update module versions prior to 7.x-2.7, update to version 7.x-2.7 or later. For LABjs module versions prior to 7.x-1.8, update to version 7.x-1.8 or later.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7943
DLA-548-1
DSA-3897-1
MGASA-2015-0425

Produtos afetados

Drupal
Labjs
Jquery Update