Open redirect in Drupal - CVE-2013-6389
Published: September 15, 2016
Vulnerability identifier: #VU457
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6389
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The weakness allows a remote attacker to obtain valid user's credential.
The vulnerability exists due to unsufficient URLs validation before showing their content. The Overlay module shows administrative pages instead of its substitution in the browser window that expose open redirect weakness.
Successful exploitation of the vulnerability may result in gaining access to the target user's data.
The vulnerability exists due to unsufficient URLs validation before showing their content. The Overlay module shows administrative pages instead of its substitution in the browser window that expose open redirect weakness.
Successful exploitation of the vulnerability may result in gaining access to the target user's data.
Affected software
Drupal
Fedora
drupal6
drupal7
Fedora
drupal6
drupal7
How to mitigate CVE-2013-6389
drupal6 - addressed in versions 6.29-1.el5, 6.29-1.el6
drupal7 - addressed in versions 7.24-1.el5, 7.24-1.el6
drupal7 - addressed in versions 7.24-1.el5, 7.24-1.el6