Open Redirect Vulnerability in Drupal by Acquia
CVE-2016-3167
7.4HIGH
What is CVE-2016-3167?
An open redirect vulnerability exists within the drupal_goto function in Drupal versions prior to 6.38, specifically when utilized with PHP versions earlier than 5.4.7. This vulnerability permits remote attackers to manipulate and redirect users to arbitrary external websites, potentially facilitating phishing attacks through double-encoded URLs in the 'destination' parameter. Such exploits can lead to loss of trust and sensitive data compromise for users of affected Drupal sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
