PT-2020-6399 · Drupal · Drupal Core

·

CVE-2020-13662

·

Published

2020-05-10

·

Updated

2024-03-06

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Drupal Core version 7.70 and prior versions.
Description The issue is related to an Open Redirect vulnerability that allows a user to be tricked into visiting a specially crafted link, redirecting them to an arbitrary external URL. This is due to insufficient input validation, which can be exploited by a remote attacker to access and compromise confidential data using a specially crafted link.
Recommendations For Drupal Core version 7.70 and prior versions, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to external URLs to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04619
BIT-DRUPAL-2020-13662
CVE-2020-13662
DLA-2250-1
DSA-4693-1
GHSA-GJQG-9RHV-QJ67

Affected Products

Drupal Core