VulnerabilityModified
CVE-2016-9451
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
MEDIUM 6.8EPSS 1.54%
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- drupal/drupal
- Source
- cve@mitre.org
References
- http://www.debian.org/security/2016/dsa-3718
- http://www.securityfocus.com/bid/94367Third Party Advisory, VDB Entry
- https://www.drupal.org/SA-CORE-2016-005Patch, Vendor Advisory
- http://www.debian.org/security/2016/dsa-3718
- http://www.securityfocus.com/bid/94367Third Party Advisory, VDB Entry
- https://www.drupal.org/SA-CORE-2016-005Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.