CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 30 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-5627 | Med | 0.40 | 6.1 | 0.01 | Sep 9, 2020 | Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack. | ||
| CVE-2020-5623 | Med | 0.40 | 6.1 | 0.01 | Aug 28, 2020 | NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack. | ||
| CVE-2020-24598 | Med | 0.40 | 6.1 | 0.01 | Aug 26, 2020 | An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect. | ||
| CVE-2020-5541 | Med | 0.40 | 6.1 | 0.01 | Aug 25, 2020 | Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL. | ||
| CVE-2020-4598 | Med | 0.40 | 6.1 | 0.01 | Aug 24, 2020 | IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect… | ||
| CVE-2020-4653 | Med | 0.40 | 6.1 | 0.01 | Aug 19, 2020 | IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to… | ||
| CVE-2019-12783 | Med | 0.40 | 6.1 | 0.01 | Jul 14, 2020 | An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "crowdsource" bruteforce login attempts… | ||
| CVE-2019-20901 | Med | 0.40 | 6.1 | 0.01 | Jul 13, 2020 | The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter. | ||
| CVE-2020-11882 | Med | 0.40 | 6.1 | 0.01 | Jul 7, 2020 | The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can be delivered either via links or by directly calling the activity. However, the deeplink format is… | ||
| CVE-2020-14454 | Med | 0.40 | 6.1 | 0.01 | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008. | ||
| CVE-2020-14446 | — | Med | 0.40 | 6.1 | 0.01 | Jun 18, 2020 | An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists. | |
| CVE-2020-3337 | Med | 0.40 | 6.1 | 0.01 | Jun 18, 2020 | A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An… | ||
| CVE-2020-1323 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'. | ||
| CVE-2020-1220 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'. | ||
| CVE-2020-13486 | Med | 0.40 | 6.1 | 0.01 | May 25, 2020 | The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection. | ||
| CVE-2020-13121 | Med | 0.40 | 6.1 | 0.03 | May 16, 2020 | Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt. | ||
| CVE-2020-5409 | Med | 0.40 | 6.1 | 0.01 | May 14, 2020 | Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access… | ||
| CVE-2020-12699 | Med | 0.40 | 6.1 | 0.01 | May 13, 2020 | The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl. | ||
| CVE-2020-3311 | Med | 0.40 | 6.1 | 0.01 | May 6, 2020 | A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker… | ||
| CVE-2020-3178 | Med | 0.40 | 6.1 | 0.01 | May 6, 2020 | Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper input validation of… |
- risk 0.40cvss 6.1epss 0.01
Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
- risk 0.40cvss 6.1epss 0.01
NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.
- risk 0.40cvss 6.1epss 0.01
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect…
- risk 0.40cvss 6.1epss 0.01
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "crowdsource" bruteforce login attempts…
- risk 0.40cvss 6.1epss 0.01
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.
- risk 0.40cvss 6.1epss 0.01
The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can be delivered either via links or by directly calling the activity. However, the deeplink format is…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
- risk 0.40cvss 6.1epss 0.01
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected device. An…
- risk 0.40cvss 6.1epss 0.02
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
- risk 0.40cvss 6.1epss 0.01
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
- risk 0.40cvss 6.1epss 0.03
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
- risk 0.40cvss 6.1epss 0.01
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website and gain access to that user's access…
- risk 0.40cvss 6.1epss 0.01
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
- risk 0.40cvss 6.1epss 0.01
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameters. An attacker…
- risk 0.40cvss 6.1epss 0.01
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper input validation of…