CVE-2017-6932
01.03.2018, 23:29
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
Vendor | Product | Version |
---|---|---|
drupal | drupal | 7.0 ≤ 𝑥 < 7.57 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References