Open redirect in Drupal - CVE-2015-3233

 

Open redirect in Drupal - CVE-2015-3233

Published: September 14, 2016


Vulnerability identifier: #VU433
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3233
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows attackers to obtain potentially sensitive information.
The weakness exists due to unproper functionality of Overlay module that unsufficiently checks the URLs. The module also shows administrative page in the browser instead of its substitution.
Successful exploitation of this vulnerability may result in obtaining potentially sensitive data.

Affected software

Drupal
Debian Linux
Fedora
drupal7

How to mitigate CVE-2015-3233


drupal7 - addressed in versions 7.38-1.el5, 7.38-1.el6, 7.38-1.el7, 7.38-1.fc21, 7.38-1.fc22

External References

Related Security Bulletins