CVE-2015-4398: Medium severity chaos tool suite (ctools) for drupal vulnerability
Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4398?
CVE-2015-4398 has a high severity due to its potential to facilitate phishing attacks.
How do I fix CVE-2015-4398?
To fix CVE-2015-4398, update the Chaos Tool Suite (Ctools) module to version 6.x-1.12 or 7.x-1.7 or newer.
What versions are affected by CVE-2015-4398?
CVE-2015-4398 affects Chaos Tool Suite (Ctools) modules prior to 6.x-1.12 and 7.x-1.7.
Can CVE-2015-4398 allow arbitrary website redirection?
Yes, CVE-2015-4398 allows remote attackers to redirect users to arbitrary websites.
What are the risks associated with CVE-2015-4398?
The main risk associated with CVE-2015-4398 is the potential for successful phishing attacks against users.