VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 21 of 85
  • CVE-2023-20884MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

  • CVE-2023-25829MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2020-21038MedMay 8, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.

  • CVE-2023-24935MedApr 11, 2023
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2023-28069MedApr 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks.

  • CVE-2023-24735MedMar 6, 2023
    risk 0.40cvss 6.1epss 0.01

    PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.

  • CVE-2023-22432MedMar 6, 2023
    risk 0.40cvss 6.1epss 0.02

    Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

  • CVE-2022-2837MedMar 3, 2023
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.

  • CVE-2022-46784MedFeb 23, 2023
    risk 0.40cvss 6.1epss 0.00

    SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)

  • CVE-2022-38779MedFeb 22, 2023
    risk 0.40cvss 6.1epss 0.01

    An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.

  • CVE-2023-23860MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP NetWeaver AS for ABAP and ABAP Platform - versions 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, allows an unauthenticated attacker to craft a link, which when clicked by an unsuspecting user can be used to redirect a user to a malicious site which could read or…

  • CVE-2023-23853MedFeb 14, 2023
    risk 0.40cvss 6.1epss 0.00

    An unauthenticated attacker in AP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, can craft a link which when clicked by an unsuspecting user can be used to redirect a user to a malicious…

  • CVE-2023-22798MedFeb 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may have been there for security purposes. This could potentially cause open redirects…

  • CVE-2023-22418MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.00

    On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated…

  • CVE-2023-24445MedJan 26, 2023
    risk 0.40cvss 6.1epss 0.01

    Jenkins OpenID Plugin 2.4 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins.

  • CVE-2023-24044MedJan 22, 2023
    risk 0.40cvss 6.1epss 0.02

    A Host Header Injection issue on the Login page of Plesk Obsidian through 18.0.49 allows attackers to redirect users to malicious websites via a Host request header. NOTE: the vendor's position is "the ability to use arbitrary domain names to access the panel is an intended…

  • CVE-2023-22298MedJan 17, 2023
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

  • CVE-2023-0042MedJan 12, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.

  • CVE-2023-22958MedJan 11, 2023
    risk 0.40cvss 6.1epss 0.00

    The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.

  • CVE-2022-3614MedJan 3, 2023
    risk 0.40cvss 6.1epss 0.00

    In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.