CVE-2015-7943: Medium severity drupal vulnerability
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7943?
CVE-2015-7943 is classified as a moderate severity vulnerability, allowing for potential phishing attacks through open redirects.
How do I fix CVE-2015-7943?
To patch CVE-2015-7943, you should upgrade your Drupal installation to versions 7.41 or later.
Which Drupal versions are affected by CVE-2015-7943?
CVE-2015-7943 affects Drupal versions prior to 7.41, including 7.0 to 7.40.
Can CVE-2015-7943 be exploited remotely?
Yes, CVE-2015-7943 allows remote attackers to exploit the vulnerability to redirect users to malicious sites.
What modules are associated with CVE-2015-7943?
CVE-2015-7943 is associated with the Overlay module, jQuery Update module, and LABjs module in Drupal.