VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 20 of 85
  • CVE-2023-40306MedSep 8, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.

  • CVE-2023-38574MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

  • CVE-2022-45582MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.

  • CVE-2022-44215MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.

  • CVE-2023-34917MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.00

    Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.

  • CVE-2023-34916MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.00

    Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.

  • CVE-2023-35791MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.00

    Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.

  • CVE-2021-36580MedJul 27, 2023
    risk 0.40cvss 6.1epss 0.02

    Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

  • CVE-2021-39425MedJul 20, 2023
    risk 0.40cvss 6.1epss 0.01

    SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

  • CVE-2023-37561MedJul 13, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows:…

  • CVE-2023-37947MedJul 12, 2023
    risk 0.40cvss 6.1epss 0.01

    Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

  • CVE-2023-3139MedJul 4, 2023
    risk 0.40cvss 6.1epss 0.01

    The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

  • CVE-2023-28364MedJul 1, 2023
    risk 0.40cvss 6.1epss 0.00

    An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.

  • CVE-2023-34415MedJun 19, 2023
    risk 0.40cvss 6.1epss 0.00

    When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on…

  • CVE-2023-24030MedJun 15, 2023
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker…

  • CVE-2023-35029MedJun 15, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPage…

  • CVE-2023-32551MedJun 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Landscape allowed URLs which caused open redirection.

  • CVE-2023-29540MedJun 2, 2023
    risk 0.40cvss 6.1epss 0.00

    Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus…

  • CVE-2023-32218MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

  • CVE-2023-23754MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.