Drupal external link injection vulnerability
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Apr 23, 2024
Description
Published by the National Vulnerability Database
Mar 1, 2018
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Apr 23, 2024
Last updated
Apr 23, 2024
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
References