CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 32 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-2764 | Med | 0.40 | 6.1 | 0.01 | Jan 28, 2020 | Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default. | ||
| CVE-2019-4631 | Med | 0.40 | 6.1 | 0.01 | Jan 28, 2020 | IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a… | ||
| CVE-2020-7936 | Med | 0.40 | 6.1 | 0.01 | Jan 23, 2020 | An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site. | ||
| CVE-2015-9540 | Med | 0.40 | 6.1 | 0.01 | Jan 4, 2020 | Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503. | ||
| CVE-2019-20225 | Med | 0.40 | 6.1 | 0.01 | Jan 2, 2020 | MyBB before 1.8.22 allows an open redirect on login. | ||
| CVE-2019-6025 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2019 | Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Advanced 7 r.4602 (7.1.3) and… | ||
| CVE-2019-6021 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2019 | Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. | ||
| CVE-2019-6020 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2019 | Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. | ||
| CVE-2018-18288 | Med | 0.40 | 6.1 | 0.01 | Dec 26, 2019 | CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection. | ||
| CVE-2019-18781 | Med | 0.40 | 6.1 | 0.02 | Dec 18, 2019 | An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site. | ||
| CVE-2019-8791 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2019 | An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect. | ||
| CVE-2019-1486 | Med | 0.40 | 6.1 | 0.01 | Dec 10, 2019 | A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'. | ||
| CVE-2016-1000107 | Med | 0.40 | 6.1 | 0.01 | Dec 10, 2019 | inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP… | ||
| CVE-2019-18451 | Med | 0.40 | 6.1 | 0.01 | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect. | ||
| CVE-2019-15688 | Med | 0.40 | 6.1 | 0.02 | Nov 26, 2019 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an… | ||
| CVE-2014-2213 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2019 | Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendmd5.php. | ||
| CVE-2019-15073 | Med | 0.40 | 6.1 | 0.01 | Nov 20, 2019 | An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities. | ||
| CVE-2018-13257 | Med | 0.40 | 6.1 | 0.01 | Nov 18, 2019 | The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page. | ||
| CVE-2019-18815 | Med | 0.40 | 6.1 | 0.01 | Nov 7, 2019 | PopojiCMS 2.0.1 allows refer= Open Redirection. | ||
| CVE-2010-2471 | Med | 0.40 | 6.1 | 0.01 | Nov 6, 2019 | Drupal versions 5.x and 6.x has open redirection |
- risk 0.40cvss 6.1epss 0.01
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
- risk 0.40cvss 6.1epss 0.01
IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a…
- risk 0.40cvss 6.1epss 0.01
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
- risk 0.40cvss 6.1epss 0.01
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
- risk 0.40cvss 6.1epss 0.01
MyBB before 1.8.22 allows an open redirect on login.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movable Type Advanced 7 r.4602 (7.1.3) and…
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
- risk 0.40cvss 6.1epss 0.01
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
- risk 0.40cvss 6.1epss 0.02
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
- risk 0.40cvss 6.1epss 0.01
An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead to an open redirect.
- risk 0.40cvss 6.1epss 0.01
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.
- risk 0.40cvss 6.1epss 0.01
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.
- risk 0.40cvss 6.1epss 0.02
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an…
- risk 0.40cvss 6.1epss 0.01
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendmd5.php.
- risk 0.40cvss 6.1epss 0.01
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities.
- risk 0.40cvss 6.1epss 0.01
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
- risk 0.40cvss 6.1epss 0.01
PopojiCMS 2.0.1 allows refer= Open Redirection.
- risk 0.40cvss 6.1epss 0.01
Drupal versions 5.x and 6.x has open redirection