VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 21 of 89
  • CVE-2023-46688MedDec 6, 2023
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.

  • CVE-2023-48815MedDec 4, 2023
    risk 0.40cvss 6.1epss 0.00

    kkFileView v4.3.0 is vulnerable to Incorrect Access Control.

  • CVE-2023-49061MedNov 21, 2023
    risk 0.40cvss 6.1epss 0.00

    An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

  • CVE-2023-41699MedNov 15, 2023
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server, Micro and Embedded (Servlet Implementation modules) allows Redirect Access to Libraries.This issue affects Payara Server, Micro and Embedded: from 5.0.0 before 5.57.0, from…

  • CVE-2023-45203MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-45202MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-45201MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-20264MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker…

  • CVE-2023-36085MedOct 25, 2023
    risk 0.40cvss 6.1epss 0.01

    The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations.…

  • CVE-2023-45909MedOct 18, 2023
    risk 0.40cvss 6.1epss 0.00

    zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.

  • CVE-2023-40779MedSep 14, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.

  • CVE-2023-41609MedSep 11, 2023
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

  • CVE-2023-40306MedSep 8, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.

  • CVE-2023-38574MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

  • CVE-2022-45582MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.

  • CVE-2022-44215MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.

  • CVE-2023-34917MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.00

    Fuge CMS v1.0 contains an Open Redirect vulnerability in member/RegisterAct.java.

  • CVE-2023-34916MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.00

    Fuge CMS v1.0 contains an Open Redirect vulnerability via /front/ProcessAct.java.

  • CVE-2023-35791MedJul 31, 2023
    risk 0.40cvss 6.1epss 0.00

    Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.

  • CVE-2021-36580MedJul 27, 2023
    risk 0.40cvss 6.1epss 0.02

    Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.