CVE-2013-6389: Input Validation
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/drupal/drupalto a version that resolves this vulnerability.Fixed in 7.24
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6389?
CVE-2013-6389 has a high severity rating due to its potential for exploitation in phishing attacks.
How do I fix CVE-2013-6389?
To fix CVE-2013-6389, you must update Drupal to version 7.24 or later.
Which versions of Drupal are affected by CVE-2013-6389?
CVE-2013-6389 affects all Drupal 7.x versions prior to 7.24, including various alpha, beta, and release candidates.
Can CVE-2013-6389 be exploited remotely?
Yes, CVE-2013-6389 can be exploited remotely by attackers to redirect users to malicious sites.
What type of vulnerability is CVE-2013-6389?
CVE-2013-6389 is classified as an open redirect vulnerability.