Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.debian.org/security/2016/dsa-3718 | |
| http://www.securityfocus.com/bid/94367 | Third Party Advisory VDB Entry | 
| https://www.drupal.org/SA-CORE-2016-005 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2016-11-25 18:59
Updated : 2017-01-07 03:00
NVD link : CVE-2016-9451
Mitre link : CVE-2016-9451
CVE.ORG link : CVE-2016-9451
JSON object : View
Products Affected
                drupal
- drupal
 
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
