CVE-2012-1589: Input Validation
Open redirect vulnerability in the Form API in Drupal 7.x before 7.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted parameters in a destination URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1589?
CVE-2012-1589 has a medium severity rating due to its potential for open redirect attacks.
How do I fix CVE-2012-1589?
To fix CVE-2012-1589, upgrade your Drupal installation to version 7.13 or later.
What versions are affected by CVE-2012-1589?
CVE-2012-1589 affects all Drupal 7.x versions prior to 7.13, including alpha, beta, and release candidate versions.
What is an open redirect vulnerability in CVE-2012-1589?
An open redirect vulnerability allows attackers to redirect users to malicious sites, potentially facilitating phishing attacks.
Who is impacted by CVE-2012-1589?
Users of Drupal versions 7.0 to 7.12 are directly impacted by CVE-2012-1589 due to the exploitability of the open redirect vulnerability.