Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published: 2018-03-01T22:00:00Z

Updated: 2024-09-17T02:01:26.822Z

Reserved: 2017-03-16T00:00:00

Link: CVE-2017-6932

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-03-01T23:29:00.560

Modified: 2018-03-22T13:53:27.650

Link: CVE-2017-6932

cve-icon Redhat

No data.