PT-2020-6399 · Drupal · Drupal Core

Vortfu

·

Published

2020-05-10

·

Updated

2024-03-06

·

CVE-2020-13662

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Core version 7.70 and prior versions.
Description The issue is related to an Open Redirect vulnerability that allows a user to be tricked into visiting a specially crafted link, redirecting them to an arbitrary external URL. This is due to insufficient input validation, which can be exploited by a remote attacker to access and compromise confidential data using a specially crafted link.
Recommendations For Drupal Core version 7.70 and prior versions, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to external URLs to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2021-04619
BIT-DRUPAL-2020-13662
CVE-2020-13662
DLA-2250-1
DSA-4693-1
GHSA-GJQG-9RHV-QJ67

Affected Products

Drupal Core