Uncontrolled external site redirect In drupal/drupal
Description
Drupal Open Redirect Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 7.13 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5.