PT-2020-6399 · Drupal · Drupal Core
Vortfu
·
Published
2020-05-10
·
Updated
2024-03-06
·
CVE-2020-13662
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Drupal Core version 7.70 and prior versions.
Description
The issue is related to an Open Redirect vulnerability that allows a user to be tricked into visiting a specially crafted link, redirecting them to an arbitrary external URL. This is due to insufficient input validation, which can be exploited by a remote attacker to access and compromise confidential data using a specially crafted link.
Recommendations
For Drupal Core version 7.70 and prior versions, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to external URLs to minimize the risk of exploitation.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Drupal Core