VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,693)

page 28 of 85
  • CVE-2020-4840MedDec 21, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a…

  • CVE-2020-4849MedDec 15, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 190294.

  • CVE-2020-26836MedDec 9, 2020
    risk 0.40cvss 6.1epss 0.02

    SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter credentials or download malicious software, as…

  • CVE-2020-27816MedDec 2, 2020
    risk 0.40cvss 6.1epss 0.01

    The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource.…

  • CVE-2020-28726MedNov 24, 2020
    risk 0.40cvss 6.1epss 0.01

    Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.

  • CVE-2020-15300MedNov 18, 2020
    risk 0.40cvss 6.1epss 0.01

    SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.

  • CVE-2020-26161MedOct 26, 2020
    risk 0.40cvss 6.1epss 0.01

    In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

  • CVE-2020-6365MedOct 15, 2020
    risk 0.40cvss 6.1epss 0.01

    SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker could execute phishing attacks to steal…

  • CVE-2020-24551MedOct 14, 2020
    risk 0.40cvss 6.1epss 0.01

    IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login credentials.

  • CVE-2020-15677MedOct 1, 2020
    risk 0.40cvss 6.1epss 0.02

    By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This…

  • CVE-2019-15974MedSep 23, 2020
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the parameters of an HTTP request. An attacker…

  • CVE-2020-5627MedSep 9, 2020
    risk 0.40cvss 6.1epss 0.01

    Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

  • CVE-2020-5623MedAug 28, 2020
    risk 0.40cvss 6.1epss 0.01

    NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

  • CVE-2020-24598MedAug 26, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.

  • CVE-2020-5541MedAug 25, 2020
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.

  • CVE-2020-4598MedAug 24, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect…

  • CVE-2020-4653MedAug 19, 2020
    risk 0.40cvss 6.1epss 0.01

    IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to…

  • CVE-2019-12783MedJul 14, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "crowdsource" bruteforce login attempts…

  • CVE-2019-20901MedJul 13, 2020
    risk 0.40cvss 6.1epss 0.01

    The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.

  • CVE-2020-11882MedJul 7, 2020
    risk 0.40cvss 6.1epss 0.01

    The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can be delivered either via links or by directly calling the activity. However, the deeplink format is…