CVE-2020-13662: Drupal

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.

Affected products

  • Drupal Drupal: from 7.0, up to and including 7.70

Published 2021-05-05. Last modified 2026-06-17.