Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
| Software | From | Fixed in |
|---|---|---|
| context_project / context | 7.x-3.1 | 7.x-3.1.x |
| context_project / context | 7.x-3.5 | 7.x-3.5.x |
| context_project / context | 7.x-3.4 | 7.x-3.4.x |
| context_project / context | 7.x-3.2 | 7.x-3.2.x |
| context_project / context | 7.x-3.0 | 7.x-3.0.x |
| context_project / context | 7.x-3.3 | 7.x-3.3.x |
| fedoraproject / fedora | 20 | 20.x |
| fedoraproject / fedora | 21 | 21.x |