VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 23 of 85
  • CVE-2022-31735MedSep 15, 2022
    risk 0.40cvss 6.1epss 0.00

    OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.

  • CVE-2022-39814MedSep 13, 2022
    risk 0.40cvss 6.1epss 0.00

    In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

  • CVE-2022-38131MedSep 6, 2022
    risk 0.40cvss 6.1epss 0.01

    RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.

  • CVE-2021-29864MedAug 30, 2022
    risk 0.40cvss 6.1epss 0.00

    IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to…

  • CVE-2022-27547MedAug 29, 2022
    risk 0.40cvss 6.1epss 0.00

    HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.

  • CVE-2022-25799MedAug 16, 2022
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authenticated user's browser could be…

  • CVE-2022-27509MedJul 28, 2022
    risk 0.40cvss 6.1epss 0.00

    Unauthenticated redirection to a malicious website

  • CVE-2022-30706MedJul 26, 2022
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

  • CVE-2022-25803MedJul 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.

  • CVE-2020-26877MedJun 29, 2022
    risk 0.40cvss 6.1epss 0.01

    ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI submitted with the authorization request, without checking…

  • CVE-2022-29272MedJun 29, 2022
    risk 0.40cvss 6.1epss 0.04

    In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

  • CVE-2022-32444MedJun 17, 2022
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.

  • CVE-2022-24969MedJun 9, 2022
    risk 0.40cvss 6.1epss 0.02

    bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.

  • CVE-2022-23237MedJun 2, 2022
    risk 0.40cvss 6.1epss 0.01

    E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

  • CVE-2022-30992MedMay 18, 2022
    risk 0.40cvss 6.1epss 0.01

    Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2022-1702MedMay 13, 2022
    risk 0.40cvss 6.1epss 0.09

    SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.

  • CVE-2022-27461MedMay 4, 2022
    risk 0.40cvss 6.1epss 0.01

    In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.

  • CVE-2021-25111MedApr 25, 2022
    risk 0.40cvss 6.1epss 0.02

    The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue

  • CVE-2020-14118MedApr 21, 2022
    risk 0.40cvss 6.1epss 0.01

    An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps.

  • CVE-2022-1254MedApr 20, 2022
    risk 0.40cvss 6.1epss 0.01

    A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a user to a malicious website controlled by…