Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade drupal7 | Feb 27, 2018 | Feb 24, 2018 |
| Drupal | — | Upgrade to drupal version 7.57 | Mar 26, 2019 | Mar 1, 2018 |
| Freebsd | — | Upgrade drupal8Upgrade drupal7 | Feb 27, 2018 | Feb 25, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 1, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub