VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 18 of 85
  • CVE-2024-5492MedJul 10, 2024
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

  • CVE-2024-37830MedJul 9, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.

  • CVE-2024-4604MedJun 26, 2024
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields. This issue affects SSO (Single Sign On): from 1.0 before 1.1.

  • CVE-2024-4900MedJun 24, 2024
    risk 0.40cvss 6.1epss 0.00

    The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post

  • CVE-2024-4940MedJun 22, 2024
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery…

  • CVE-2024-23442MedJun 14, 2024
    risk 0.40cvss 6.1epss 0.00

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2024-3032MedJun 13, 2024
    risk 0.40cvss 6.1epss 0.01

    Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

  • CVE-2024-23664MedJun 3, 2024
    risk 0.40cvss 6.1epss 0.00

    A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

  • CVE-2024-4133MedMay 2, 2024
    risk 0.40cvss 6.1epss 0.01

    The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.30. This is due to insufficient validation on the redirect url supplied via the…

  • CVE-2024-21065MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-31135MedMar 28, 2024
    risk 0.40cvss 6.1epss 0.00

    In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

  • CVE-2024-0337MedMar 20, 2024
    risk 0.40cvss 6.1epss 0.01

    The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious…

  • CVE-2023-44308MedFeb 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.

  • CVE-2024-22854MedFeb 16, 2024
    risk 0.40cvss 6.1epss 0.00

    DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential…

  • CVE-2024-21728MedFeb 15, 2024
    risk 0.40cvss 6.1epss 0.00

    An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control…

  • CVE-2024-0250MedFeb 12, 2024
    risk 0.40cvss 6.1epss 0.01

    The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious…

  • CVE-2024-24034MedFeb 8, 2024
    risk 0.40cvss 6.1epss 0.01

    Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.

  • CVE-2024-24291MedFeb 6, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

  • CVE-2024-0953MedFeb 5, 2024
    risk 0.40cvss 6.1epss 0.00

    When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.

  • CVE-2024-22113MedJan 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary websites and conduct phishing attacks via a specially crafted URL.