VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,693)

page 32 of 85
  • CVE-2019-15818MedAug 30, 2019
    risk 0.40cvss 6.1epss 0.01

    The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.

  • CVE-2019-15771MedAug 29, 2019
    risk 0.40cvss 6.1epss 0.01

    The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

  • CVE-2019-15776MedAug 29, 2019
    risk 0.40cvss 6.1epss 0.01

    The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.

  • CVE-2019-15775MedAug 29, 2019
    risk 0.40cvss 6.1epss 0.01

    The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

  • CVE-2019-15774MedAug 29, 2019
    risk 0.40cvss 6.1epss 0.02

    The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

  • CVE-2019-15773MedAug 29, 2019
    risk 0.40cvss 6.1epss 0.01

    The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

  • CVE-2019-15772MedAug 29, 2019
    risk 0.40cvss 6.1epss 0.01

    The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.

  • CVE-2016-6154MedAug 23, 2019
    risk 0.40cvss 6.1epss 0.01

    The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).

  • CVE-2019-13422MedAug 23, 2019
    risk 0.40cvss 6.1epss 0.01

    Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.

  • CVE-2019-11589MedAug 23, 2019
    risk 0.40cvss 6.1epss 0.01

    The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cross-site request forgery (CSRF) token, via…

  • CVE-2019-11585MedAug 23, 2019
    risk 0.40cvss 6.1epss 0.01

    The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open…

  • CVE-2019-1954MedAug 8, 2019
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP…

  • CVE-2016-10769MedAug 5, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).

  • CVE-2018-20929MedAug 1, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).

  • CVE-2018-20867MedJul 30, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).

  • CVE-2019-1020016MedJul 29, 2019
    risk 0.40cvss 6.1epss 0.01

    ASH-AIO before 2.0.0.3 allows an open redirect.

  • CVE-2019-1010290MedJul 16, 2019
    risk 0.40cvss 6.1epss 0.04

    Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker.…

  • CVE-2019-1075MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.03

    A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

  • CVE-2018-12621MedJul 5, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.

  • CVE-2019-5969MedJul 5, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.