VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 17 of 85
  • CVE-2024-54050MedDec 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.

  • CVE-2024-25566MedOct 29, 2024
    risk 0.40cvss 6.1epss 0.00

    An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing attacks

  • CVE-2024-42930MedOct 28, 2024
    risk 0.40cvss 6.1epss 0.00

    PbootCMS 3.2.8 is vulnerable to URL Redirect.

  • CVE-2024-46326MedOct 21, 2024
    risk 0.40cvss 6.1epss 0.00

    Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.

  • CVE-2024-45247MedOct 6, 2024
    risk 0.40cvss 6.1epss 0.00

    Sonarr – CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

  • CVE-2024-43683MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.

  • CVE-2024-8148MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2024-38037MedOct 4, 2024
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2024-8883MedSep 19, 2024
    risk 0.40cvss 6.1epss 0.02

    A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the…

  • CVE-2024-8897MedSep 17, 2024
    risk 0.40cvss 6.1epss 0.07

    Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug…

  • CVE-2024-8761HigSep 17, 2024
    risk 0.40cvss 7.2epss 0.00

    The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users…

  • CVE-2024-7312MedSep 11, 2024
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before…

  • CVE-2024-7260MedSep 9, 2024
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is…

  • CVE-2024-8586MedSep 9, 2024
    risk 0.40cvss 6.1epss 0.00

    WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks.

  • CVE-2024-42341MedSep 8, 2024
    risk 0.40cvss 6.1epss 0.00

    Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

  • CVE-2024-8386MedSep 3, 2024
    risk 0.40cvss 6.1epss 0.00

    If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

  • CVE-2024-44776MedAug 29, 2024
    risk 0.40cvss 6.1epss 0.00

    An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.

  • CVE-2024-27184MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..

  • CVE-2024-6289MedJul 15, 2024
    risk 0.40cvss 6.1epss 0.01

    The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

  • CVE-2024-6149MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5