PT-2017-7300 · Drupal · Jquery Update+2
Pere Orga
+1
·
Publicado
2015-11-04
·
Atualizado
2017-11-08
·
CVE-2015-7943
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal versions prior to 7.41
jQuery Update module versions prior to 7.x-2.7 for Drupal
LABjs module versions prior to 7.x-1.8 for Drupal
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This is due to an incomplete fix for a previous issue.
Recommendations
For Drupal versions prior to 7.41, update to version 7.41 or later.
For jQuery Update module versions prior to 7.x-2.7, update to version 7.x-2.7 or later.
For LABjs module versions prior to 7.x-1.8, update to version 7.x-1.8 or later.
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Drupal
Labjs
Jquery Update