Description
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1295-1 | drupal7 security update |
EUVD |
EUVD-2022-5594 | Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site. |
Github GHSA |
GHSA-wm86-w3cf-h6vm | Drupal external link injection vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: drupal
Published:
Updated: 2024-09-17T02:01:26.822Z
Reserved: 2017-03-16T00:00:00.000Z
Link: CVE-2017-6932
No data.
Status : Modified
Published: 2018-03-01T23:29:00.560
Modified: 2024-11-21T03:30:50.257
Link: CVE-2017-6932
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA