VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 20 of 89
  • CVE-2024-4133MedMay 2, 2024
    risk 0.40cvss 6.1epss 0.01

    The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.0.30. This is due to insufficient validation on the redirect url supplied via the…

  • CVE-2024-21065MedApr 16, 2024
    risk 0.40cvss 6.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-31135MedMar 28, 2024
    risk 0.40cvss 6.1epss 0.00

    In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

  • CVE-2024-0337MedMar 20, 2024
    risk 0.40cvss 6.1epss 0.01

    The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to insufficient validation on the travelpayouts_redirect variable. This makes it possible for unauthenticated attackers to redirect users to potentially malicious…

  • CVE-2023-44308MedFeb 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to redirect users to arbitrary external URLs via the _com_liferay_adaptive_media_web_portlet_AMPortlet_redirect parameter.

  • CVE-2024-22854MedFeb 16, 2024
    risk 0.40cvss 6.1epss 0.00

    DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows open redirect and potential credential…

  • CVE-2024-21728MedFeb 15, 2024
    risk 0.40cvss 6.1epss 0.00

    An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect vulnerability allows attackers to control…

  • CVE-2024-0250MedFeb 12, 2024
    risk 0.40cvss 6.1epss 0.01

    The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious…

  • CVE-2024-24034MedFeb 8, 2024
    risk 0.40cvss 6.1epss 0.01

    Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.

  • CVE-2024-24291MedFeb 6, 2024
    risk 0.40cvss 6.1epss 0.00

    An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

  • CVE-2024-0953MedFeb 5, 2024
    risk 0.40cvss 6.1epss 0.00

    When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.

  • CVE-2024-22113MedJan 22, 2024
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary websites and conduct phishing attacks via a specially crafted URL.

  • CVE-2023-3771MedJan 16, 2024
    risk 0.40cvss 6.1epss 0.01

    The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect users to arbitrary websites.

  • CVE-2023-49394MedJan 10, 2024
    risk 0.40cvss 6.1epss 0.00

    Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.

  • CVE-2023-48003MedDec 26, 2023
    risk 0.40cvss 6.1epss 0.00

    An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages.

  • CVE-2023-50297MedDec 26, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in PowerCMS (6 Series, 5 Series, and 4 Series) allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life,…

  • CVE-2020-17484MedDec 16, 2023
    risk 0.40cvss 6.1epss 0.00

    An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.

  • CVE-2023-6380MedDec 13, 2023
    risk 0.40cvss 6.1epss 0.02

    Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of…

  • CVE-2023-28874MedDec 9, 2023
    risk 0.40cvss 6.1epss 0.00

    The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.

  • CVE-2023-48928MedDec 8, 2023
    risk 0.40cvss 6.1epss 0.00

    Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.