CVE-2016-9451

MEDIUM6.8EPSS 0.12%

Drupal Open Redirect

Published: 5/17/2022Modified: 4/23/2024

Description

Confirmation forms in Drupal 7.x before 7.52 make it easier for remote authenticated users to conduct open redirect attacks via unspecified vectors.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.8CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

References (5)