CVE-2016-3167

high
Published 2016-04-12 · Modified 2024-04-23
CVSS v3
7.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
CVSS v2
6.4
VIR risk
7.4

Description

Drupal Open redirect vulnerability in the drupal_goto function

Predictions

Exploit likelihood
82%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.drupal.org/SA-CORE-2016-001

OS impact

OSVersionStatusFixed in
debian debian7.0affected
debian debian8.0affected

Package impact

EcosystemPackageVulnerableFixed
php Packagistdrupal/core>=6.0,<6.386.38
php Packagistdrupal/drupal>=6.0,<6.386.38

Application impact

VendorProductVersionsFixed
phpphp{"endIncluding":"5.4.6"}
drupaldrupal6.0
drupaldrupal6.1
drupaldrupal6.2
drupaldrupal6.3
drupaldrupal6.4
drupaldrupal6.5
drupaldrupal6.6
drupaldrupal6.7
drupaldrupal6.8
drupaldrupal6.9
drupaldrupal6.10
drupaldrupal6.11
drupaldrupal6.12
drupaldrupal6.13
drupaldrupal6.14
drupaldrupal6.15
drupaldrupal6.16
drupaldrupal6.17
drupaldrupal6.18
drupaldrupal6.19
drupaldrupal6.20
drupaldrupal6.21
drupaldrupal6.22
drupaldrupal6.23
drupaldrupal6.24
drupaldrupal6.25
drupaldrupal6.26
drupaldrupal6.27
drupaldrupal6.28
drupaldrupal6.29
drupaldrupal6.30
drupaldrupal6.31
drupaldrupal6.32
drupaldrupal6.33
drupaldrupal6.34
drupaldrupal6.35
drupaldrupal6.36
drupaldrupal6.37

References

Verify integrity in audit chain (admin only). AS-IS.