{"id":"GHSA-x6v2-xmrq-574j","aliases":[],"url":"https://o3.security/vulnerability/GHSA-x6v2-xmrq-574j","summary":"Drupal Anonymous Open Redirect","details":"Drupal core and contributed modules frequently use a \"destination\" query string parameter in URLs to redirect users to a new destination after completing an action on the current page. Under certain circumstances, malicious users can use this parameter to construct a URL that will trick users into being redirected to a 3rd party website, thereby exposing the users to potential social engineering attacks.","published":"2024-05-15T20:54:52Z","modified":"2024-11-29T05:49:20.135941Z","cvss":{"score":5.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.5.8"},{"ecosystem":"Packagist","name":"drupal/drupal","fixedVersion":"8.6.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/2018-10-17-3.yaml"},{"type":"PACKAGE","url":"https://github.com/drupal/drupal"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2018-006"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:49:20.135941Z"}}