CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 19 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-8883 | Med | 0.40 | 6.1 | 0.02 | Sep 19, 2024 | A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the… | ||
| CVE-2024-8897 | Med | 0.40 | 6.1 | 0.08 | Sep 17, 2024 | Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug… | ||
| CVE-2024-8761 | Hig | 0.40 | 7.2 | 0.00 | Sep 17, 2024 | The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users… | ||
| CVE-2024-7312 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before… | ||
| CVE-2024-7260 | Med | 0.40 | 6.1 | 0.01 | Sep 9, 2024 | An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is… | ||
| CVE-2024-8586 | Med | 0.40 | 6.1 | 0.00 | Sep 9, 2024 | WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks. | ||
| CVE-2024-42341 | Med | 0.40 | 6.1 | 0.00 | Sep 8, 2024 | Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | ||
| CVE-2024-8386 | Med | 0.40 | 6.1 | 0.00 | Sep 3, 2024 | If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2. | ||
| CVE-2024-44776 | Med | 0.40 | 6.1 | 0.00 | Aug 29, 2024 | An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL. | ||
| CVE-2024-27184 | Med | 0.40 | 6.1 | 0.00 | Aug 20, 2024 | Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.. | ||
| CVE-2024-6289 | Med | 0.40 | 6.1 | 0.01 | Jul 15, 2024 | The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page. | ||
| CVE-2024-6149 | Med | 0.40 | 6.1 | 0.00 | Jul 10, 2024 | Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5 | ||
| CVE-2024-5492 | Med | 0.40 | 6.1 | 0.01 | Jul 10, 2024 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | ||
| CVE-2024-37830 | Med | 0.40 | 6.1 | 0.00 | Jul 9, 2024 | An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie. | ||
| CVE-2024-4604 | Med | 0.40 | 6.1 | 0.00 | Jun 26, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields. This issue affects SSO (Single Sign On): from 1.0 before 1.1. | ||
| CVE-2024-4900 | Med | 0.40 | 6.1 | 0.00 | Jun 24, 2024 | The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post | ||
| CVE-2024-4940 | Med | 0.40 | 6.1 | 0.01 | Jun 22, 2024 | An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery… | ||
| CVE-2024-23442 | Med | 0.40 | 6.1 | 0.00 | Jun 14, 2024 | An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL. | ||
| CVE-2024-3032 | Med | 0.40 | 6.1 | 0.01 | Jun 13, 2024 | Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue | ||
| CVE-2024-23664 | Med | 0.40 | 6.1 | 0.00 | Jun 3, 2024 | A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL. |
- risk 0.40cvss 6.1epss 0.02
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the…
- risk 0.40cvss 6.1epss 0.08
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be able to spoof the address bar contents. This can lead to a malicious site to appear to have the same URL as the trusted site. *This bug…
- risk 0.40cvss 7.2epss 0.00
The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users…
- risk 0.40cvss 6.1epss 0.00
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.2020.2 before…
- risk 0.40cvss 6.1epss 0.01
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is…
- risk 0.40cvss 6.1epss 0.00
WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks.
- risk 0.40cvss 6.1epss 0.00
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- risk 0.40cvss 6.1epss 0.00
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
- risk 0.40cvss 6.1epss 0.00
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malicious site via a crafted URL.
- risk 0.40cvss 6.1epss 0.00
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
- risk 0.40cvss 6.1epss 0.01
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
- risk 0.40cvss 6.1epss 0.00
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway
- risk 0.40cvss 6.1epss 0.00
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.
- risk 0.40cvss 6.1epss 0.00
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Manipulating Hidden Fields. This issue affects SSO (Single Sign On): from 1.0 before 1.1.
- risk 0.40cvss 6.1epss 0.00
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform Open redirect attacks against any user viewing a malicious post
- risk 0.40cvss 6.1epss 0.01
An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery…
- risk 0.40cvss 6.1epss 0.00
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
- risk 0.40cvss 6.1epss 0.01
Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
- risk 0.40cvss 6.1epss 0.00
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.