Drupal SA-CONTRIB-2009-080: Simplenews Statistics Open Redirect

high Nessus Plugin ID 42254

Synopsis

The remote web server hosts a PHP application that is affected by an open redirect vulnerability.

Description

The version of Drupal running on the remote web server includes the third-party Simplenews Statistics module, which provides newsletter statistics such as open and click-through rates.

The version of Simplenews Statistics installed contains an open redirect, which can be used in a phishing attack to trick users into visiting malicious sites.

Solution

Upgrade to Simplenews Statistics version 6.x-2.0 or later.

See Also

https://www.drupal.org/node/611002

Plugin Details

Severity: High

ID: 42254

File Name: drupal_simplenews_statistics_url_redirect.nasl

Version: 1.19

Type: remote

Family: CGI abuses

Published: 10/24/2009

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.0

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2009-3784

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:drupal:drupal, cpe:/a:sjoerd_arendsen:simplenews_statistics

Required KB Items: installed_sw/Drupal, www/PHP

Exploit Ease: No known exploits are available

Patch Publication Date: 10/21/2009

Vulnerability Publication Date: 10/21/2009

Reference Information

CVE: CVE-2009-3784

BID: 36790

CWE: 352

SECUNIA: 37128