Description
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.
Remediation
References
Related Vulnerabilities
IBM WebSEAL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2023-38371)
Envoy Proxy Excessive Iteration Vulnerability (CVE-2021-39204)
WebLogic CVE-2018-3252 Vulnerability (CVE-2018-3252)
Oracle JRE CVE-2023-21939 Vulnerability (CVE-2023-21939)
WordPress Plugin Video.js-HTML5 Video Player for Wordpress Cross-Site Scripting (3.2.3)