4.9

CVE-2015-3378

Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to the break lock page for edited views.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Views Project ≫ Views SwPlatform drupal Version <= 6.x-2.16
Views Project ≫ Views Version 6.x-3.0 SwPlatform drupal
Views Project ≫ Views Version 6.x-3.0 Update alpha1 SwPlatform drupal
Views Project ≫ Views Version 6.x-3.0 Update alpha2 SwPlatform drupal
Views Project ≫ Views Version 6.x-3.0 Update alpha3 SwPlatform drupal
Views Project ≫ Views Version 6.x-3.0 Update alpha4 SwPlatform drupal
Views Project ≫ Views Version 6.x-3.0 Update rc2 SwPlatform drupal
Views Project ≫ Views Version 6.x-3.0 Update rc3 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.0 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.0 Update alpha1 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.0 Update beta1 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.0 Update beta2 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.0 Update beta3 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.0 Update rc1 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.0 Update rc3 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.1 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.2 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.3 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.4 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.5 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.6 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.7 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.8 SwPlatform drupal
Views Project ≫ Views Version 7.x-3.x Update dev SwPlatform drupal
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.57% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.9 6.8 4.9
AV:N/AC:M/Au:S/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.openwall.com/lists/oss-security/2015/02/13/12
http://www.securityfocus.com/bid/72590
https://www.drupal.org/node/2424097
Patch
https://www.drupal.org/node/2424101
Patch
https://www.drupal.org/node/2424103
Patch
https://www.drupal.org/node/2424403
Patch
Vendor Advisory