VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 22 of 89
  • CVE-2021-39425MedJul 20, 2023
    risk 0.40cvss 6.1epss 0.01

    SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

  • CVE-2023-37561MedJul 13, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows:…

  • CVE-2023-37947MedJul 12, 2023
    risk 0.40cvss 6.1epss 0.01

    Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks.

  • CVE-2023-3139MedJul 4, 2023
    risk 0.40cvss 6.1epss 0.01

    The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

  • CVE-2023-28364MedJul 1, 2023
    risk 0.40cvss 6.1epss 0.00

    An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now the user must manually navigate to the URL.

  • CVE-2023-34415MedJun 19, 2023
    risk 0.40cvss 6.1epss 0.00

    When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on…

  • CVE-2023-24030MedJun 15, 2023
    risk 0.40cvss 6.1epss 0.00

    An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0 and 8.8.15. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker…

  • CVE-2023-35029MedJun 15, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPage…

  • CVE-2023-32551MedJun 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Landscape allowed URLs which caused open redirection.

  • CVE-2023-29540MedJun 2, 2023
    risk 0.40cvss 6.1epss 0.00

    Using a redirect embedded into sourceMappingUrls could allow for navigation to external protocol links in sandboxed iframes without allow-top-navigation-to-custom-protocols. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus…

  • CVE-2023-32218MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

  • CVE-2023-23754MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.

  • CVE-2023-20884MedMay 30, 2023
    risk 0.40cvss 6.1epss 0.00

    VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.

  • CVE-2023-25829MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.

  • CVE-2020-21038MedMay 8, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.

  • CVE-2023-24935MedApr 11, 2023
    risk 0.40cvss 6.1epss 0.01

    Microsoft Edge (Chromium-based) Spoofing Vulnerability

  • CVE-2023-28069MedApr 5, 2023
    risk 0.40cvss 6.1epss 0.00

    Dell Streaming Data Platform prior to 1.4 contains Open Redirect vulnerability. A remote unauthenticated attacker can phish the legitimate user to redirect to malicious website leading to information disclosure and launch of phishing attacks.

  • CVE-2023-24735MedMar 6, 2023
    risk 0.40cvss 6.1epss 0.01

    PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.

  • CVE-2023-22432MedMar 6, 2023
    risk 0.40cvss 6.1epss 0.02

    Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.

  • CVE-2022-2837MedMar 3, 2023
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in coreDNS. This flaw allows a malicious user to redirect traffic intended for external top-level domains (TLD) to a pod they control by creating projects and namespaces that match the TLD.