VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,693)

page 31 of 85
  • CVE-2019-18781MedDec 18, 2019
    risk 0.40cvss 6.1epss 0.02

    An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.

  • CVE-2019-8791MedDec 18, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.

  • CVE-2019-19709MedDec 11, 2019
    risk 0.40cvss 6.1epss 0.02

    MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.

  • CVE-2019-1486MedDec 10, 2019
    risk 0.40cvss 6.1epss 0.01

    A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.

  • CVE-2016-1000107MedDec 10, 2019
    risk 0.40cvss 6.1epss 0.01

    inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP…

  • CVE-2019-18451MedNov 26, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

  • CVE-2019-15688MedNov 26, 2019
    risk 0.40cvss 6.1epss 0.02

    Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an…

  • CVE-2014-2213MedNov 22, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendmd5.php.

  • CVE-2019-15073MedNov 20, 2019
    risk 0.40cvss 6.1epss 0.01

    An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.

  • CVE-2018-13257MedNov 18, 2019
    risk 0.40cvss 6.1epss 0.01

    The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.

  • CVE-2019-18815MedNov 7, 2019
    risk 0.40cvss 6.1epss 0.01

    PopojiCMS 2.0.1 allows refer= Open Redirection.

  • CVE-2010-2471MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.01

    Drupal versions 5.x and 6.x has open redirection

  • CVE-2010-3661MedNov 1, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.

  • CVE-2019-15041MedOct 1, 2019
    risk 0.40cvss 6.1epss 0.01

    JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.

  • CVE-2019-14912MedSep 20, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.

  • CVE-2019-16393MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

  • CVE-2019-6004MedSep 12, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2019-5978MedSep 12, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.

  • CVE-2019-14223MedSep 6, 2019
    risk 0.40cvss 6.1epss 0.04

    An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attacker can redirect a victim to a malicious…

  • CVE-2019-15820MedAug 30, 2019
    risk 0.40cvss 6.1epss 0.01

    The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.