5.8
CVE-2015-3371
- EPSS 1.2%
- Veröffentlicht 21.04.2015 16:59:29
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Node Invite Project ≫ Node Invite SwPlatformdrupal Version <= 6.x-2.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.2% | 0.642 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://www.openwall.com/lists/oss-security/2015/01/29/6
http://www.securityfocus.com/bid/74287
https://www.drupal.org/node/2415541
https://www.drupal.org/node/2415899