CVE Vulnerabilities

CVE-2015-4398

Published: Jun 16, 2015 | Modified: Jun 25, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors involving processing confirmation delete pages.

Affected Software

Name Vendor Start Version End Version
Ctools Chaos_tool_suite_project * 6.x-1.11 (including)
Ctools Chaos_tool_suite_project 7.x-1.0 (including) 7.x-1.0 (including)
Ctools Chaos_tool_suite_project 7.x-1.1 (including) 7.x-1.1 (including)
Ctools Chaos_tool_suite_project 7.x-1.2 (including) 7.x-1.2 (including)
Ctools Chaos_tool_suite_project 7.x-1.3 (including) 7.x-1.3 (including)
Ctools Chaos_tool_suite_project 7.x-1.4 (including) 7.x-1.4 (including)
Ctools Chaos_tool_suite_project 7.x-1.5 (including) 7.x-1.5 (including)
Ctools Chaos_tool_suite_project 7.x-1.6 (including) 7.x-1.6 (including)

References