VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 12 of 85
  • CVE-2023-30433MedJul 19, 2023
    risk 0.42cvss 6.5epss 0.00

    IBM Security Verify Access 10.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a…

  • CVE-2023-33405MedJun 21, 2023
    risk 0.42cvss 6.1epss 0.31

    Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.

  • CVE-2023-23855MedFeb 14, 2023
    risk 0.42cvss 6.5epss 0.00

    SAP Solution Manager - version 720, allows an authenticated attacker to redirect users to a malicious site due to insufficient URL validation. A successful attack could lead an attacker to read or modify the information or expose the user to a phishing attack. As a result, it…

  • CVE-2022-39183MedJan 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.

  • CVE-2022-34478MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    The ms-msdt, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none…

  • CVE-2022-20794MedMay 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an…

  • CVE-2022-20764MedMay 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Multiple vulnerabilities in the web engine of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, view sensitive data on an affected device, or redirect users to an…

  • CVE-2022-24794HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is…

  • CVE-2021-3654MedMar 2, 2022
    risk 0.42cvss 6.1epss 0.27

    A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

  • CVE-2021-31252MedJun 4, 2021
    risk 0.42cvss 6.1epss 0.29

    An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.

  • CVE-2019-6781HigMay 17, 2019
    risk 0.42cvss 7.5epss 0.01

    An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

  • CVE-2018-15798HigDec 19, 2018
    risk 0.42cvss 7.6epss 0.01

    Pivotal Concourse Release, versions 4.x prior to 4.2.2, login flow allows redirects to untrusted websites. A remote unauthenticated attacker could convince a user to click on a link using the oAuth redirect link with an untrusted website and gain access to that user's access…

  • CVE-2017-15419MedAug 28, 2018
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.

  • CVE-2011-1594MedFeb 5, 2014
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks,…

  • CVE-2024-58342MedApr 1, 2026
    risk 0.41cvss 6.3epss 0.00

    XenForo before 2.2.17 and 2.3.1 allows open redirect via a specially crafted URL. The getDynamicRedirect() function does not adequately validate the redirect target, allowing attackers to redirect users to arbitrary external sites using crafted URLs containing newlines, user…

  • CVE-2024-13983MedNov 14, 2025
    risk 0.41cvss 6.3epss 0.00

    Inappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a crafted QR code. (Chromium security severity: Low)

  • CVE-2024-12924MedSep 1, 2025
    risk 0.41cvss 6.3epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Akınsoft QR Menü allows Forceful Browsing, Phishing. This issue affects QR Menü: from s1.05.05 before v1.05.12.

  • CVE-2025-55625MedAug 22, 2025
    risk 0.41cvss 6.3epss 0.00

    An open redirect vulnerability in Reolink v4.54.0.4.20250526 allows attackers to redirect users to a malicious site via a crafted URL. NOTE: this is disputed by the Supplier because it is intentional behavior that supports redirection to Alexa URLs, which are not guaranteed to…

  • CVE-2024-34328MedJul 31, 2025
    risk 0.41cvss 6.3epss 0.00

    An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack via a crafted URL.

  • CVE-2025-3522MedApr 15, 2025
    risk 0.41cvss 6.3epss 0.00

    Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird accesses the specified URL to determine file size, and navigates to it when the user clicks the attachment. Because the…