MGASA-2015-0425

Source
https://advisories.mageia.org/MGASA-2015-0425.html
Import Source
https://advisories.mageia.org/MGASA-2015-0425.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0425
Upstream
  • CVE-2015-7943
Published
2015-11-04T18:03:05Z
Modified
2026-04-16T06:26:08.595260004Z
Summary
Updated drupal package fixes security vulnerability
Details

The Overlay module in Drupal core displays administrative pages as a layer over the current page (using JavaScript), rather than replacing the page in the browser window. The Overlay module does not sufficiently validate URLs prior to displaying their contents, leading to an open redirect vulnerability (CVE-2015-7943).

References
Credits

Affected packages

Mageia:5 / drupal

Package

Name
drupal
Purl
pkg:rpm/mageia/drupal?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.41-1.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0425.json"