CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 24 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-46288 | Med | 0.40 | 6.1 | 0.01 | Dec 19, 2022 | Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL. | ||
| CVE-2022-41275 | Med | 0.40 | 6.1 | 0.00 | Dec 13, 2022 | In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing… | ||
| CVE-2022-37927 | Med | 0.40 | 6.1 | 0.00 | Dec 12, 2022 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD). | ||
| CVE-2022-45917 | Med | 0.40 | 6.1 | 0.02 | Dec 7, 2022 | ILIAS before 7.16 has an Open Redirect. | ||
| CVE-2022-43479 | Med | 0.40 | 6.1 | 0.01 | Dec 5, 2022 | Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack. | ||
| CVE-2021-22141 | Med | 0.40 | 6.1 | 0.01 | Nov 18, 2022 | An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website. | ||
| CVE-2022-38201 | Med | 0.40 | 6.1 | 0.01 | Nov 15, 2022 | An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain. | ||
| CVE-2022-41207 | Med | 0.40 | 6.1 | 0.00 | Nov 8, 2022 | SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or… | ||
| CVE-2022-39021 | Med | 0.40 | 6.1 | 0.01 | Oct 31, 2022 | U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user to arbitrary website. | ||
| CVE-2022-38197 | Med | 0.40 | 6.1 | 0.01 | Oct 25, 2022 | Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker controlled website via a crafted query parameter. | ||
| CVE-2022-26954 | Med | 0.40 | 6.1 | 0.01 | Oct 20, 2022 | Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync… | ||
| CVE-2022-31735 | Med | 0.40 | 6.1 | 0.01 | Sep 15, 2022 | OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website. | ||
| CVE-2022-39814 | Med | 0.40 | 6.1 | 0.00 | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter. | ||
| CVE-2022-38131 | Med | 0.40 | 6.1 | 0.02 | Sep 6, 2022 | RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites. | ||
| CVE-2021-29864 | Med | 0.40 | 6.1 | 0.00 | Aug 30, 2022 | IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to… | ||
| CVE-2022-27547 | Med | 0.40 | 6.1 | 0.01 | Aug 29, 2022 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc. | ||
| CVE-2022-25799 | Med | 0.40 | 6.1 | 0.01 | Aug 16, 2022 | An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authenticated user's browser could be… | ||
| CVE-2022-27509 | Med | 0.40 | 6.1 | 0.00 | Jul 28, 2022 | Unauthenticated redirection to a malicious website | ||
| CVE-2022-30706 | Med | 0.40 | 6.1 | 0.01 | Jul 26, 2022 | Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL. | ||
| CVE-2022-25803 | Med | 0.40 | 6.1 | 0.01 | Jul 14, 2022 | Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search. |
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- risk 0.40cvss 6.1epss 0.00
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing…
- risk 0.40cvss 6.1epss 0.00
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashboard (OVGD).
- risk 0.40cvss 6.1epss 0.02
ILIAS before 7.16 has an Open Redirect.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.
- risk 0.40cvss 6.1epss 0.01
An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.
- risk 0.40cvss 6.1epss 0.01
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.
- risk 0.40cvss 6.1epss 0.00
SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting victim, it will use an unsensitized parameter to redirect the victim to a malicious site of the attacker's choosing which can result in disclosure or…
- risk 0.40cvss 6.1epss 0.01
U-Office Force login function has an Open Redirect vulnerability. An unauthenticated remote attacker can exploit this vulnerability to redirect user to arbitrary website.
- risk 0.40cvss 6.1epss 0.01
Esri ArcGIS Server versions 10.9.1 and below have an unvalidated redirect issue that may allow a remote, unauthenticated attacker to phish a user into accessing an attacker controlled website via a crafted query parameter.
- risk 0.40cvss 6.1epss 0.01
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync…
- risk 0.40cvss 6.1epss 0.01
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary website.
- risk 0.40cvss 6.1epss 0.00
In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
- risk 0.40cvss 6.1epss 0.02
RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.
- risk 0.40cvss 6.1epss 0.00
IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to…
- risk 0.40cvss 6.1epss 0.01
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
- risk 0.40cvss 6.1epss 0.01
An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authenticated user's browser could be…
- risk 0.40cvss 6.1epss 0.00
Unauthenticated redirection to a malicious website
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- risk 0.40cvss 6.1epss 0.01
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.