{"id":"GHSA-6gf6-24h2-66j4","summary":"Drupal core Open Redirect vulnerability","details":"Drupal 7 has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL.\n\nThe vulnerability is caused by insufficient validation of the destination query parameter in the drupal_goto() function.\n\nOther versions of Drupal core are not vulnerable.","modified":"2024-05-15T20:48:59Z","published":"2024-05-15T20:48:59Z","database_specific":{"github_reviewed_at":"2024-05-15T20:48:59Z","nvd_published_at":null,"cwe_ids":["CWE-601"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/2020-05-20-1.yaml"},{"type":"PACKAGE","url":"https://github.com/drupal/core"},{"type":"WEB","url":"https://www.drupal.org/sa-core-2020-003"}],"affected":[{"package":{"name":"drupal/core","ecosystem":"Packagist","purl":"pkg:composer/drupal/core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.70"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-6gf6-24h2-66j4/GHSA-6gf6-24h2-66j4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}