CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 22 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39425 | Med | 0.40 | 6.1 | 0.01 | Jul 20, 2023 | SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links. | ||
| CVE-2023-37561 | Med | 0.40 | 6.1 | 0.00 | Jul 13, 2023 | Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows:… | ||
| CVE-2023-37947 | Med | 0.40 | 6.1 | 0.01 | Jul 12, 2023 | Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | ||
| CVE-2023-3139 | Med | 0.40 | 6.1 | 0.01 | Jul 4, 2023 | The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered. | ||
| CVE-2023-28364 | Med | 0.40 | 6.1 | 0.00 | Jul 1, 2023 | An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL. | ||
| CVE-2023-34415 | Med | 0.40 | 6.1 | 0.00 | Jun 19, 2023 | When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on… | ||
| CVE-2023-24030 | Med | 0.40 | 6.1 | 0.00 | Jun 15, 2023 | An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker… | ||
| CVE-2023-35029 | Med | 0.40 | 6.1 | 0.00 | Jun 15, 2023 | Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPage… | ||
| CVE-2023-32551 | Med | 0.40 | 6.1 | 0.00 | Jun 6, 2023 | Landscape allowed URLs which caused open redirection. | ||
| CVE-2023-29540 | Med | 0.40 | 6.1 | 0.00 | Jun 2, 2023 | Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus… | ||
| CVE-2023-32218 | Med | 0.40 | 6.1 | 0.00 | May 30, 2023 | Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | ||
| CVE-2023-23754 | Med | 0.40 | 6.1 | 0.00 | May 30, 2023 | An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen. | ||
| CVE-2023-20884 | Med | 0.40 | 6.1 | 0.00 | May 30, 2023 | VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure. | ||
| CVE-2023-25829 | Med | 0.40 | 6.1 | 0.00 | May 9, 2023 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks. | ||
| CVE-2020-21038 | Med | 0.40 | 6.1 | 0.00 | May 8, 2023 | Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. | ||
| CVE-2023-24935 | Med | 0.40 | 6.1 | 0.01 | Apr 11, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-28069 | Med | 0.40 | 6.1 | 0.00 | Apr 5, 2023 | Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks. | ||
| CVE-2023-24735 | Med | 0.40 | 6.1 | 0.01 | Mar 6, 2023 | PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL. | ||
| CVE-2023-22432 | Med | 0.40 | 6.1 | 0.02 | Mar 6, 2023 | Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack. | ||
| CVE-2022-2837 | Med | 0.40 | 6.1 | 0.00 | Mar 3, 2023 | A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD. |
- risk 0.40cvss 6.1epss 0.01
SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- risk 0.40cvss 6.1epss 0.00
Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows:…
- risk 0.40cvss 6.1epss 0.01
Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.
- risk 0.40cvss 6.1epss 0.01
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
- risk 0.40cvss 6.1epss 0.00
An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.
- risk 0.40cvss 6.1epss 0.00
When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on…
- risk 0.40cvss 6.1epss 0.00
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker…
- risk 0.40cvss 6.1epss 0.00
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPage…
- risk 0.40cvss 6.1epss 0.00
Landscape allowed URLs which caused open redirection.
- risk 0.40cvss 6.1epss 0.00
Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus…
- risk 0.40cvss 6.1epss 0.00
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
- risk 0.40cvss 6.1epss 0.00
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.
- risk 0.40cvss 6.1epss 0.00
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
- risk 0.40cvss 6.1epss 0.00
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
- risk 0.40cvss 6.1epss 0.00
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.00
Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks.
- risk 0.40cvss 6.1epss 0.01
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.
- risk 0.40cvss 6.1epss 0.02
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.
- risk 0.40cvss 6.1epss 0.00
A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.