CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 21 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46688 | Med | 0.40 | 6.1 | 0.01 | Dec 6, 2023 | Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL. | ||
| CVE-2023-48815 | Med | 0.40 | 6.1 | 0.00 | Dec 4, 2023 | kkFileView v4.3.0 is vulnerable to Incorrect Access Control. | ||
| CVE-2023-49061 | Med | 0.40 | 6.1 | 0.00 | Nov 21, 2023 | An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120. | ||
| CVE-2023-41699 | Med | 0.40 | 6.1 | 0.00 | Nov 15, 2023 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from… | ||
| CVE-2023-45203 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | ||
| CVE-2023-45202 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | ||
| CVE-2023-45201 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | ||
| CVE-2023-20264 | Med | 0.40 | 6.1 | 0.00 | Nov 1, 2023 | A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker… | ||
| CVE-2023-36085 | Med | 0.40 | 6.1 | 0.01 | Oct 25, 2023 | The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations.… | ||
| CVE-2023-45909 | Med | 0.40 | 6.1 | 0.00 | Oct 18, 2023 | zzzcms v2.2.0 was discovered to contain an open redirect vulnerability. | ||
| CVE-2023-40779 | Med | 0.40 | 6.1 | 0.01 | Sep 14, 2023 | An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL. | ||
| CVE-2023-41609 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2023 | An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL. | ||
| CVE-2023-40306 | Med | 0.40 | 6.1 | 0.00 | Sep 8, 2023 | SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity. | ||
| CVE-2023-38574 | Med | 0.40 | 6.1 | 0.01 | Sep 5, 2023 | Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. | ||
| CVE-2022-45582 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2023 | Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter. | ||
| CVE-2022-44215 | Med | 0.40 | 6.1 | 0.01 | Aug 22, 2023 | There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL. | ||
| CVE-2023-34917 | Med | 0.40 | 6.1 | 0.00 | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java. | ||
| CVE-2023-34916 | Med | 0.40 | 6.1 | 0.00 | Jul 31, 2023 | Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java. | ||
| CVE-2023-35791 | Med | 0.40 | 6.1 | 0.00 | Jul 31, 2023 | Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability. | ||
| CVE-2021-36580 | Med | 0.40 | 6.1 | 0.02 | Jul 27, 2023 | Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter. |
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.
- risk 0.40cvss 6.1epss 0.00
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
- risk 0.40cvss 6.1epss 0.00
An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.
- risk 0.40cvss 6.1epss 0.00
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from…
- risk 0.40cvss 6.1epss 0.00
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- risk 0.40cvss 6.1epss 0.00
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- risk 0.40cvss 6.1epss 0.00
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
- risk 0.40cvss 6.1epss 0.00
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker…
- risk 0.40cvss 6.1epss 0.01
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations.…
- risk 0.40cvss 6.1epss 0.00
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
- risk 0.40cvss 6.1epss 0.00
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
- risk 0.40cvss 6.1epss 0.00
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
- risk 0.40cvss 6.1epss 0.01
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
- risk 0.40cvss 6.1epss 0.01
There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
- risk 0.40cvss 6.1epss 0.00
Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.
- risk 0.40cvss 6.1epss 0.00
Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.
- risk 0.40cvss 6.1epss 0.00
Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.
- risk 0.40cvss 6.1epss 0.02
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.