ZeroHour

CVE-2017-6932

CVSS 3.0
4.7 medium
EPSS
1%p66
Published
()
Modified
Description

Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.

Vendors
drupaldebian
Products
drupal, debian linux
Ecosystems
Drupal
Weakness
CWE-601
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.