Description
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
Remediation
References
Related Vulnerabilities
WordPress Plugin PICA Photo Gallery 'picaPhotosResize.php' Arbitrary File Upload (1.0)
WordPress Plugin Mobile Booster Security Bypass (1.0)
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2021-38268)
WordPress Plugin Zingiri Web Shop Unspecified Vulnerability (2.6.5)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46816)