CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,692)
page 19 of 85| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3771 | Med | 0.40 | 6.1 | 0.01 | Jan 16, 2024 | The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites. | ||
| CVE-2023-49394 | Med | 0.40 | 6.1 | 0.00 | Jan 10, 2024 | Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly. | ||
| CVE-2023-48003 | Med | 0.40 | 6.1 | 0.00 | Dec 26, 2023 | An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages. | ||
| CVE-2023-50297 | Med | 0.40 | 6.1 | 0.00 | Dec 26, 2023 | Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life,… | ||
| CVE-2020-17484 | Med | 0.40 | 6.1 | 0.00 | Dec 16, 2023 | An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain. | ||
| CVE-2023-6380 | Med | 0.40 | 6.1 | 0.02 | Dec 13, 2023 | Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of… | ||
| CVE-2023-28874 | Med | 0.40 | 6.1 | 0.00 | Dec 9, 2023 | The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites. | ||
| CVE-2023-48928 | Med | 0.40 | 6.1 | 0.00 | Dec 8, 2023 | Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | ||
| CVE-2023-46688 | Med | 0.40 | 6.1 | 0.01 | Dec 6, 2023 | Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. | ||
| CVE-2023-48815 | Med | 0.40 | 6.1 | 0.00 | Dec 4, 2023 | kkFileView v4.3.0 is vulnerable to Incorrect Access Control. | ||
| CVE-2023-49061 | Med | 0.40 | 6.1 | 0.00 | Nov 21, 2023 | An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120. | ||
| CVE-2023-41699 | Med | 0.40 | 6.1 | 0.00 | Nov 15, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from… | ||
| CVE-2023-45203 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | ||
| CVE-2023-45202 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | ||
| CVE-2023-45201 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | ||
| CVE-2023-20264 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker… | ||
| CVE-2023-36085 | Med | 0.40 | 6.1 | 0.01 | Oct 25, 2023 | The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations.… | ||
| CVE-2023-45909 | Med | 0.40 | 6.1 | 0.00 | Oct 18, 2023 | zzzcms v2.2.0 was discovered to contain an open redirect vulnerability. | ||
| CVE-2023-40779 | Med | 0.40 | 6.1 | 0.01 | Sep 14, 2023 | An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL. | ||
| CVE-2023-41609 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2023 | An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL. |
- risk 0.40cvss 6.1epss 0.01
The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.
- risk 0.40cvss 6.1epss 0.00
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
- risk 0.40cvss 6.1epss 0.00
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.
- risk 0.40cvss 6.1epss 0.00
Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life,…
- risk 0.40cvss 6.1epss 0.00
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
- risk 0.40cvss 6.1epss 0.02
Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of…
- risk 0.40cvss 6.1epss 0.00
The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
- risk 0.40cvss 6.1epss 0.00
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.
- risk 0.40cvss 6.1epss 0.00
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
- risk 0.40cvss 6.1epss 0.00
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
- risk 0.40cvss 6.1epss 0.00
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from…
- risk 0.40cvss 6.1epss 0.00
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- risk 0.40cvss 6.1epss 0.00
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- risk 0.40cvss 6.1epss 0.00
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- risk 0.40cvss 6.1epss 0.00
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker…
- risk 0.40cvss 6.1epss 0.01
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations.…
- risk 0.40cvss 6.1epss 0.00
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
- risk 0.40cvss 6.1epss 0.00
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.