Open redirect in Drupal - CVE-2016-9451
Published: November 25, 2016 / Updated: August 9, 2020
Vulnerability identifier: #VU40006
CSH Severity: Low
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N]
CVE-ID: CVE-2016-9451
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to manipulate data.
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
Affected software
Drupal
Fedora
drupal7
Fedora
drupal7
How to mitigate CVE-2016-9451
Install update from vendor's website.
drupal7 - addressed in versions 7.52-1.el5, 7.52-1.el6, 7.52-1.el7, 7.52-1.fc23, 7.52-1.fc24, 7.52-1.fc25