Open redirect in Drupal - CVE-2013-6389

 

Open redirect in Drupal - CVE-2013-6389

Published: September 15, 2016


Vulnerability identifier: #VU457
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6389
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The weakness allows a remote attacker to obtain valid user's credential.
The vulnerability exists due to unsufficient URLs validation before showing their content. The Overlay module shows administrative pages instead of its substitution in the browser window that expose open redirect weakness.
Successful exploitation of the vulnerability may result in gaining access to the target user's data.

Affected software

Drupal
Fedora
drupal6
drupal7

How to mitigate CVE-2013-6389


drupal6 - addressed in versions 6.29-1.el5, 6.29-1.el6
drupal7 - addressed in versions 7.24-1.el5, 7.24-1.el6

External References

Related Security Bulletins