{"id":"GHSA-7f4f-p7mq-p4fv","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7f4f-p7mq-p4fv","summary":"Drupal External URL injection through URL aliases leading to Open Redirect","details":"The path module in Drupal allows users with the 'administer paths' to create pretty URLs for content.\nIn certain circumstances the user can enter a particular path that triggers an open redirect to a malicious url.","published":"2024-05-15T20:24:16Z","modified":"2024-11-29T05:49:13.822092Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"7.60"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.5.8"},{"ecosystem":"Packagist","name":"drupal/core","fixedVersion":"8.6.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/2018-10-17-2.yaml"},{"type":"PACKAGE","url":"https://github.com/drupal/core"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2018-006"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:49:13.822092Z"}}