CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,692)
page 20 of 85| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-40306 | Med | 0.40 | 6.1 | 0.00 | Sep 8, 2023 | SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity. | ||
| CVE-2023-38574 | Med | 0.40 | 6.1 | 0.00 | Sep 5, 2023 | Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. | ||
| CVE-2022-45582 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2023 | Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. | ||
| CVE-2022-44215 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2023 | There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL. | ||
| CVE-2023-34917 | Med | 0.40 | 6.1 | 0.00 | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java. | ||
| CVE-2023-34916 | Med | 0.40 | 6.1 | 0.00 | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java. | ||
| CVE-2023-35791 | Med | 0.40 | 6.1 | 0.00 | Jul 31, 2023 | Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability. | ||
| CVE-2021-36580 | Med | 0.40 | 6.1 | 0.02 | Jul 27, 2023 | Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter. | ||
| CVE-2021-39425 | Med | 0.40 | 6.1 | 0.01 | Jul 20, 2023 | SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links. | ||
| CVE-2023-37561 | Med | 0.40 | 6.1 | 0.00 | Jul 13, 2023 | Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows:… | ||
| CVE-2023-37947 | Med | 0.40 | 6.1 | 0.01 | Jul 12, 2023 | Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | ||
| CVE-2023-3139 | Med | 0.40 | 6.1 | 0.01 | Jul 4, 2023 | The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered. | ||
| CVE-2023-28364 | Med | 0.40 | 6.1 | 0.00 | Jul 1, 2023 | An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL. | ||
| CVE-2023-34415 | Med | 0.40 | 6.1 | 0.00 | Jun 19, 2023 | When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on… | ||
| CVE-2023-24030 | Med | 0.40 | 6.1 | 0.00 | Jun 15, 2023 | An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker… | ||
| CVE-2023-35029 | Med | 0.40 | 6.1 | 0.00 | Jun 15, 2023 | Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPage… | ||
| CVE-2023-32551 | Med | 0.40 | 6.1 | 0.00 | Jun 6, 2023 | Landscape allowed URLs which caused open redirection. | ||
| CVE-2023-29540 | Med | 0.40 | 6.1 | 0.00 | Jun 2, 2023 | Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus… | ||
| CVE-2023-32218 | Med | 0.40 | 6.1 | 0.00 | May 30, 2023 | Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | ||
| CVE-2023-23754 | Med | 0.40 | 6.1 | 0.00 | May 30, 2023 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. |
- risk 0.40cvss 6.1epss 0.00
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
- risk 0.40cvss 6.1epss 0.00
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
- risk 0.40cvss 6.1epss 0.01
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
- risk 0.40cvss 6.1epss 0.01
There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
- risk 0.40cvss 6.1epss 0.00
Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.
- risk 0.40cvss 6.1epss 0.00
Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.
- risk 0.40cvss 6.1epss 0.00
Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.
- risk 0.40cvss 6.1epss 0.02
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
- risk 0.40cvss 6.1epss 0.01
SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- risk 0.40cvss 6.1epss 0.00
Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows:…
- risk 0.40cvss 6.1epss 0.01
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
- risk 0.40cvss 6.1epss 0.01
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
- risk 0.40cvss 6.1epss 0.00
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.
- risk 0.40cvss 6.1epss 0.00
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on…
- risk 0.40cvss 6.1epss 0.00
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker…
- risk 0.40cvss 6.1epss 0.00
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPage…
- risk 0.40cvss 6.1epss 0.00
Landscape allowed URLs which caused open redirection.
- risk 0.40cvss 6.1epss 0.00
Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus…
- risk 0.40cvss 6.1epss 0.00
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.