6.8
CVSSv3

CVE-2016-9451

Published: 25/11/2016 Updated: 07/01/2017
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.8 | Impact Score: 4 | Exploitability Score: 2.3
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

Confirmation forms in Drupal 7.x prior to 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

drupal drupal 7.0

drupal drupal 7.11

drupal drupal 7.12

drupal drupal 7.19

drupal drupal 7.2

drupal drupal 7.27

drupal drupal 7.28

drupal drupal 7.34

drupal drupal 7.35

drupal drupal 7.42

drupal drupal 7.43

drupal drupal 7.1

drupal drupal 7.10

drupal drupal 7.17

drupal drupal 7.18

drupal drupal 7.24

drupal drupal 7.25

drupal drupal 7.26

drupal drupal 7.32

drupal drupal 7.33

drupal drupal 7.40

drupal drupal 7.41

drupal drupal 7.13

drupal drupal 7.14

drupal drupal 7.20

drupal drupal 7.21

drupal drupal 7.29

drupal drupal 7.3

drupal drupal 7.36

drupal drupal 7.37

drupal drupal 7.44

drupal drupal 7.50

drupal drupal 7.15

drupal drupal 7.16

drupal drupal 7.22

drupal drupal 7.23

drupal drupal 7.30

drupal drupal 7.31

drupal drupal 7.38

drupal drupal 7.4

drupal drupal 7.51

Vendor Advisories

Multiple vulnerabilities has been found in the Drupal content management framework For additional information, please refer to the upstream advisory at wwwdrupalorg/SA-CORE-2016-005 For the stable distribution (jessie), this problem has been fixed in version 732-1+deb8u8 For the unstable distribution (sid), this problem has been fixed ...
Under certain circumstances, malicious users could construct a URL to a confirmation form that would trick users into being redirected to a 3rd party website after interacting with the form, thereby exposing the users to potential social engineering attacks ...