VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 26 of 89
  • CVE-2021-45408MedFeb 4, 2022
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.

  • CVE-2022-22919MedJan 30, 2022
    risk 0.40cvss 6.1epss 0.01

    Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.

  • CVE-2021-25074MedJan 24, 2022
    risk 0.40cvss 6.1epss 0.02

    The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

  • CVE-2021-25028MedJan 24, 2022
    risk 0.40cvss 6.1epss 0.02

    The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

  • CVE-2021-24838MedJan 17, 2022
    risk 0.40cvss 6.1epss 0.02

    The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vendor, is a feature.

  • CVE-2021-38678MedJan 14, 2022
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following versions of…

  • CVE-2021-20875MedDec 24, 2021
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by…

  • CVE-2021-40852MedDec 17, 2021
    risk 0.40cvss 6.1epss 0.01

    TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.

  • CVE-2020-18985MedDec 15, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.

  • CVE-2021-43532MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.01

    The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one…

  • CVE-2021-43058MedNov 1, 2021
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, redirecting the user to an…

  • CVE-2021-22942MedOct 18, 2021
    risk 0.40cvss 6.1epss 0.02

    A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.

  • CVE-2021-22963MedOct 14, 2021
    risk 0.40cvss 6.1epss 0.01

    A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications…

  • CVE-2021-20806MedOct 13, 2021
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2021-23052MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious user to build an open redirect URI. Note: Software versions…

  • CVE-2021-32805HigSep 8, 2021
    risk 0.40cvss 7.2epss 0.01

    Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, this URL can redirect a user…

  • CVE-2021-39501MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.04

    EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.

  • CVE-2021-38123MedSep 7, 2021
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious websites after authentication.

  • CVE-2021-37352MedAug 13, 2021
    risk 0.40cvss 6.1epss 0.06

    An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.

  • CVE-2021-22098MedAug 11, 2021
    risk 0.40cvss 6.1epss 0.01

    UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a…