Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
CVSS Details
- CVSS 3.0 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade drupal7 | Aug 30, 2017 | Aug 24, 2015 |
| Debian | — | Upgrade drupal7 | Mar 31, 2017 | Oct 21, 2015 |
| Drupal | — | Upgrade to Drupal version 7.41 | Aug 2, 2017 | Jul 4, 2017 |
| Freebsd | — | Upgrade drupal7 | Dec 10, 2025 | Oct 24, 2015 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub