Impact
Drupal core contains a flaw that permits attackers to manipulate a URL redirection parameter so that a visitor is sent to an untrusted site, leading to open redirect and cache poisoning. The weakness, identified as CWE‑601, can be used to display malicious content that appears to originate from the trusted Drupal environment, facilitating phishing and credential theft while also potentially misdirecting cached content to compromise state.
Affected Systems
All Drupal core releases are affected: every version from 0.0.0 through 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, and all 11.0.x and 11.1.x builds. In short, any supported Drupal core installation prior to the fix is vulnerable.
Risk and Exploitability
By inserting a specially crafted link, a user can be redirected to an external site of the attacker’s choosing, potentially delivering poisoned cached content or phishing material. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, indicating no confirmed widespread exploitation at this time. The CVSS score of 5.9 shows a moderate impact, but this does not diminish the potential for social‑engineering attacks against high‑traffic sites; the open‑redirect path remains exploitable until a patch or mitigative configuration is applied.
OpenCVE Enrichment