VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 19 of 85
  • CVE-2023-3771MedJan 16, 2024
    risk 0.40cvss 6.1epss 0.01

    The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

  • CVE-2023-49394MedJan 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.

  • CVE-2023-48003MedDec 26, 2023
    risk 0.40cvss 6.1epss 0.00

    An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

  • CVE-2023-50297MedDec 26, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life,…

  • CVE-2020-17484MedDec 16, 2023
    risk 0.40cvss 6.1epss 0.00

    An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.

  • CVE-2023-6380MedDec 13, 2023
    risk 0.40cvss 6.1epss 0.02

    Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of…

  • CVE-2023-28874MedDec 9, 2023
    risk 0.40cvss 6.1epss 0.00

    The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

  • CVE-2023-48928MedDec 8, 2023
    risk 0.40cvss 6.1epss 0.00

    Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-46688MedDec 6, 2023
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.

  • CVE-2023-48815MedDec 4, 2023
    risk 0.40cvss 6.1epss 0.00

    kkFileView v4.3.0 is vulnerable to Incorrect Access Control.

  • CVE-2023-49061MedNov 21, 2023
    risk 0.40cvss 6.1epss 0.00

    An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

  • CVE-2023-41699MedNov 15, 2023
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from…

  • CVE-2023-45203MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-45202MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-45201MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-20264MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker…

  • CVE-2023-36085MedOct 25, 2023
    risk 0.40cvss 6.1epss 0.01

    The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations.…

  • CVE-2023-45909MedOct 18, 2023
    risk 0.40cvss 6.1epss 0.00

    zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.

  • CVE-2023-40779MedSep 14, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

  • CVE-2023-41609MedSep 11, 2023
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.