ZeroHour

CVE-2016-3164

CVSS 3.0
7.4 high
EPSS
2%p79
Published
()
Modified
Description

Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

Vendors
drupaldebian
Products
drupal, debian linux
Ecosystems
Drupal
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.