5.8
CVE-2015-4398
- EPSS 0.48%
- Veröffentlicht 16.06.2015 17:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Chaos Tool Suite Project ≫ Ctools SwPlatformdrupal Version <= 6.x-1.11
Chaos Tool Suite Project ≫ Ctools Version7.x-1.0 SwPlatformdrupal
Chaos Tool Suite Project ≫ Ctools Version7.x-1.1 SwPlatformdrupal
Chaos Tool Suite Project ≫ Ctools Version7.x-1.2 SwPlatformdrupal
Chaos Tool Suite Project ≫ Ctools Version7.x-1.3 SwPlatformdrupal
Chaos Tool Suite Project ≫ Ctools Version7.x-1.4 SwPlatformdrupal
Chaos Tool Suite Project ≫ Ctools Version7.x-1.5 SwPlatformdrupal
Chaos Tool Suite Project ≫ Ctools Version7.x-1.6 SwPlatformdrupal
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.62 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|