VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 22 of 85
  • CVE-2022-38208MedDec 29, 2022
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2022-45413MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    Using the S.browser_fallback_url parameter parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects…

  • CVE-2022-36316MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL had been subject to a redirect. This vulnerability affects Firefox < 103.

  • CVE-2022-34474MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    Even when an iframe was sandboxed with allow-top-navigation-by-user-activation, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affects Firefox < 102.

  • CVE-2022-29912MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.01

    Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29910MedDec 22, 2022
    risk 0.40cvss 6.1epss 0.00

    When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.*Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 100.

  • CVE-2022-47500MedDec 19, 2022
    risk 0.40cvss 6.1epss 0.01

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI…

  • CVE-2022-38662MedDec 19, 2022
    risk 0.40cvss 6.1epss 0.00

     In HCL Digital Experience, URLs can be constructed to redirect users to untrusted sites.

  • CVE-2022-46288MedDec 19, 2022
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

  • CVE-2022-41275MedDec 13, 2022
    risk 0.40cvss 6.1epss 0.00

    In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing…

  • CVE-2022-37927MedDec 12, 2022
    risk 0.40cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).

  • CVE-2022-45917MedDec 7, 2022
    risk 0.40cvss 6.1epss 0.02

    ILIAS before 7.16 has an Open Redirect.

  • CVE-2022-43479MedDec 5, 2022
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.

  • CVE-2021-22141MedNov 18, 2022
    risk 0.40cvss 6.1epss 0.01

    An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

  • CVE-2022-38201MedNov 15, 2022
    risk 0.40cvss 6.1epss 0.00

    An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.

  • CVE-2022-41207MedNov 8, 2022
    risk 0.40cvss 6.1epss 0.00

    SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or…

  • CVE-2022-39021MedOct 31, 2022
    risk 0.40cvss 6.1epss 0.01

    U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user to arbitrary website.

  • CVE-2022-38197MedOct 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker controlled website via a crafted query parameter.

  • CVE-2022-26954MedOct 20, 2022
    risk 0.40cvss 6.1epss 0.01

    Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync…

  • CVE-2022-31735MedSep 15, 2022
    risk 0.40cvss 6.1epss 0.00

    OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.