VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 27 of 89
  • CVE-2021-33707MedAug 10, 2021
    risk 0.40cvss 6.1epss 0.02

    SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.

  • CVE-2021-33331MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect'…

  • CVE-2021-21579MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

  • CVE-2021-21578MedAug 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

  • CVE-2021-37746MedJul 30, 2021
    risk 0.40cvss 6.1epss 0.01

    textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.

  • CVE-2021-20789MedJul 30, 2021
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote…

  • CVE-2020-5329MedJul 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links.

  • CVE-2021-35966MedJul 19, 2021
    risk 0.40cvss 6.1epss 0.01

    The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.

  • CVE-2021-35037MedJul 12, 2021
    risk 0.40cvss 6.1epss 0.01

    Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that appears to be for a customer's Jamf Pro instance, but when clicked will forward a user to an…

  • CVE-2021-24406MedJul 6, 2021
    risk 0.40cvss 6.1epss 0.03

    The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website…

  • CVE-2021-34807MedJul 2, 2021
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the token is obtained, an attacker could…

  • CVE-2021-20105MedJun 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.

  • CVE-2021-34254MedJun 28, 2021
    risk 0.40cvss 6.1epss 0.01

    Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.

  • CVE-2020-18660MedJun 23, 2021
    risk 0.40cvss 6.1epss 0.01

    GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.

  • CVE-2010-4266MedJun 22, 2021
    risk 0.40cvss 6.1epss 0.01

    It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.

  • CVE-2021-32956MedJun 18, 2021
    risk 0.40cvss 6.1epss 0.01

    Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.

  • CVE-2021-24358MedJun 14, 2021
    risk 0.40cvss 6.1epss 0.02

    The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.

  • CVE-2021-22903MedJun 11, 2021
    risk 0.40cvss 6.1epss 0.01

    The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. This…

  • CVE-2020-18268MedJun 7, 2021
    risk 0.40cvss 6.1epss 0.03

    Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."

  • CVE-2021-25640MedJun 1, 2021
    risk 0.40cvss 6.1epss 0.02

    In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.