VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 16 of 85
  • CVE-2024-12561MedMay 21, 2025
    risk 0.40cvss 6.1epss 0.00

    The Affiliate Sales in Google Analytics and other tools plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.0.0. This is due to insufficient validation on the redirect url supplied via the 'afflink' parameter. This makes it possible for…

  • CVE-2025-40630MedMay 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Open redirection vulnerability in IceWarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to redirect a user to any domain by sending a malicious URL to the victim, for example “ https://icewarp.domain.com//<MALICIOUS_DOMAIN>/%2e%2e”…

  • CVE-2024-6690MedMay 15, 2025
    risk 0.40cvss 6.1epss 0.01

    The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

  • CVE-2023-6786MedMay 15, 2025
    risk 0.40cvss 6.1epss 0.00

    The Payment Gateway for Telcell WordPress plugin through 2.0.1 does not validate the api_url parameter before redirecting the user to its value, leading to an Open Redirect issue

  • CVE-2025-30010MedMay 13, 2025
    risk 0.40cvss 6.1epss 0.00

    The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a…

  • CVE-2025-3859MedApr 30, 2025
    risk 0.40cvss 6.1epss 0.00

    Websites directing users to long URLs that caused eliding to occur in the location view could leverage the truncating behavior to potentially trick users into thinking they were on a different webpage. This vulnerability was fixed in Focus 138.

  • CVE-2024-49706MedApr 14, 2025
    risk 0.40cvss 6.1epss 0.00

    Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79.0

  • CVE-2025-3433MedApr 8, 2025
    risk 0.40cvss 6.1epss 0.00

    The Advanced Advertising System plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.1. This is due to insufficient validation on the redirect url supplied via the 'redir' parameter. This makes it possible for unauthenticated attackers to…

  • CVE-2025-3027MedMar 31, 2025
    risk 0.40cvss 6.1epss 0.00

    The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnerability could allow users to be…

  • CVE-2024-9308MedMar 20, 2025
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

  • CVE-2024-8021MedMar 20, 2025
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect…

  • CVE-2024-11044MedMar 20, 2025
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute…

  • CVE-2024-10908MedMar 20, 2025
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.

  • CVE-2024-10812MedMar 20, 2025
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This can be exploited by attackers…

  • CVE-2025-1300MedFeb 28, 2025
    risk 0.40cvss 6.1epss 0.00

    CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. The CodeChecker web server contains an open redirect vulnerability due to missing protections against multiple slashes after the product name in the URL. This…

  • CVE-2024-54957MedFeb 27, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.

  • CVE-2024-13888HigFeb 20, 2025
    risk 0.40cvss 7.2epss 0.01

    The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect…

  • CVE-2025-21512MedJan 21, 2025
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2025-23086MedJan 21, 2025
    risk 0.40cvss 6.1epss 0.00

    On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download a file. However the origin was not correctly inferred in some cases. When…

  • CVE-2024-54051MedDec 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.