CVE-2015-7943
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and…
Does this matter?
Lower severity and a low EPSS score (1.77%). Track it; it rarely justifies an emergency change on its own.
Description
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- drupal/drupal · jquery update project/jquery update · labjs project/labjs
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2017/dsa-3897Third Party Advisory
- http://www.securityfocus.com/bid/77293Third Party Advisory, VDB Entry
- https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2015-10-21/drupal-core-overlay-less-criticalVendor Advisory
- https://www.drupal.org/node/2598426Vendor Advisory
- https://www.drupal.org/node/2598434Vendor Advisory
- http://www.debian.org/security/2017/dsa-3897Third Party Advisory
- http://www.securityfocus.com/bid/77293Third Party Advisory, VDB Entry
- https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2015-10-21/drupal-core-overlay-less-criticalVendor Advisory
- https://www.drupal.org/node/2598426Vendor Advisory
- https://www.drupal.org/node/2598434Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.