VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 25 of 85
  • CVE-2021-43532MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.01

    The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one…

  • CVE-2021-43058MedNov 1, 2021
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, redirecting the user to an…

  • CVE-2021-22942MedOct 18, 2021
    risk 0.40cvss 6.1epss 0.02

    A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

  • CVE-2021-22963MedOct 14, 2021
    risk 0.40cvss 6.1epss 0.01

    A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications…

  • CVE-2021-20806MedOct 13, 2021
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2021-23052MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious user to build an open redirect URI. Note: Software versions…

  • CVE-2021-32805HigSep 8, 2021
    risk 0.40cvss 7.2epss 0.01

    Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, this URL can redirect a user…

  • CVE-2021-39501MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.04

    EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.

  • CVE-2021-38123MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.

  • CVE-2021-37352MedAug 13, 2021
    risk 0.40cvss 6.1epss 0.06

    An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.

  • CVE-2021-22098MedAug 11, 2021
    risk 0.40cvss 6.1epss 0.01

    UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a…

  • CVE-2021-33707MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.02

    SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.

  • CVE-2021-33331MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect'…

  • CVE-2021-21579MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

  • CVE-2021-21578MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

  • CVE-2021-37746MedJul 30, 2021
    risk 0.40cvss 6.1epss 0.01

    textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.

  • CVE-2021-20789MedJul 30, 2021
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote…

  • CVE-2020-5329MedJul 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

  • CVE-2021-35966MedJul 19, 2021
    risk 0.40cvss 6.1epss 0.01

    The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.

  • CVE-2021-35037MedJul 12, 2021
    risk 0.40cvss 6.1epss 0.01

    Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that appears to be for a customer's Jamf Pro instance, but when clicked will forward a user to an…