VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,693)

page 33 of 85
  • CVE-2019-5965MedJul 5, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2019-10721MedJul 3, 2019
    risk 0.40cvss 6.1epss 0.01

    BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.

  • CVE-2019-13175MedJul 2, 2019
    risk 0.40cvss 6.1epss 0.01

    Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites).

  • CVE-2019-7275MedJul 1, 2019
    risk 0.40cvss 6.1epss 0.09

    Optergy Proton/Enterprise devices allow Open Redirect.

  • CVE-2019-13038MedJun 29, 2019
    risk 0.40cvss 6.1epss 0.01

    mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.

  • CVE-2017-14394MedJun 19, 2019
    risk 0.40cvss 6.1epss 0.01

    OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.

  • CVE-2019-3477MedJun 7, 2019
    risk 0.40cvss 6.1epss 0.01

    Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.

  • CVE-2019-4201MedJun 6, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL…

  • CVE-2018-13384MedJun 4, 2019
    risk 0.40cvss 6.1epss 0.01

    A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

  • CVE-2019-5946MedMay 17, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the Login Screen.

  • CVE-2019-10117MedMay 16, 2019
    risk 0.40cvss 6.1epss 0.01

    An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

  • CVE-2019-8951MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.01

    An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote attacker to redirect users to an arbitrary URL. Affected hardware products: Bosch DIVAR IP 2000 (vulnerable versions: 3.10;…

  • CVE-2018-12300MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.03

    Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.

  • CVE-2018-14931MedApr 30, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.

  • CVE-2019-4166MedApr 30, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a…

  • CVE-2019-10955MedApr 25, 2019
    risk 0.40cvss 6.1epss 0.03

    In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370…

  • CVE-2019-4092MedApr 25, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect…

  • CVE-2019-8995MedApr 24, 2019
    risk 0.40cvss 6.1epss 0.01

    The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain a vulnerability wherein a malicious URL…

  • CVE-2018-20698MedApr 9, 2019
    risk 0.40cvss 6.1epss 0.01

    The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.

  • CVE-2019-11016MedApr 8, 2019
    risk 0.40cvss 6.1epss 0.01

    Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.