First published: Fri May 18 2012(Updated: )
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Drupal Drupal | =7.0 | |
Drupal Drupal | =7.0-alpha1 | |
Drupal Drupal | =7.0-alpha2 | |
Drupal Drupal | =7.0-alpha3 | |
Drupal Drupal | =7.0-alpha4 | |
Drupal Drupal | =7.0-alpha5 | |
Drupal Drupal | =7.0-alpha6 | |
Drupal Drupal | =7.0-alpha7 | |
Drupal Drupal | =7.0-beta1 | |
Drupal Drupal | =7.0-beta2 | |
Drupal Drupal | =7.0-beta3 | |
Drupal Drupal | =7.0-dev | |
Drupal Drupal | =7.0-rc1 | |
Drupal Drupal | =7.0-rc2 | |
Drupal Drupal | =7.0-rc3 | |
Drupal Drupal | =7.0-rc4 | |
Drupal Drupal | =7.1 | |
Drupal Drupal | =7.2 | |
Drupal Drupal | =7.3 | |
Drupal Drupal | =7.4 | |
Drupal Drupal | =7.5 | |
Drupal Drupal | =7.6 | |
Drupal Drupal | =7.7 | |
Drupal Drupal | =7.8 | |
Drupal Drupal | =7.9 | |
Drupal Drupal | =7.10 | |
Drupal Drupal | =7.11 | |
Drupal Drupal | =7.12 | |
Drupal Drupal | =7.x-dev |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1589 has a medium severity rating due to its potential for open redirect attacks.
To fix CVE-2012-1589, upgrade your Drupal installation to version 7.13 or later.
CVE-2012-1589 affects all Drupal 7.x versions prior to 7.13, including alpha, beta, and release candidate versions.
An open redirect vulnerability allows attackers to redirect users to malicious sites, potentially facilitating phishing attacks.
Users of Drupal versions 7.0 to 7.12 are directly impacted by CVE-2012-1589 due to the exploitability of the open redirect vulnerability.