VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,772)

page 35 of 89
  • CVE-2016-10769MedAug 5, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).

  • CVE-2018-20929MedAug 1, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).

  • CVE-2018-20867MedJul 30, 2019
    risk 0.40cvss 6.1epss 0.01

    cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).

  • CVE-2019-1020016MedJul 29, 2019
    risk 0.40cvss 6.1epss 0.01

    ASH-AIO before 2.0.0.3 allows an open redirect.

  • CVE-2019-1010290MedJul 16, 2019
    risk 0.40cvss 6.1epss 0.04

    Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker.…

  • CVE-2019-1075MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.03

    A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

  • CVE-2018-12621MedJul 5, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.

  • CVE-2019-5969MedJul 5, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.

  • CVE-2019-5965MedJul 5, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2019-10721MedJul 3, 2019
    risk 0.40cvss 6.1epss 0.01

    BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.

  • CVE-2019-13175MedJul 2, 2019
    risk 0.40cvss 6.1epss 0.01

    Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites).

  • CVE-2019-7275MedJul 1, 2019
    risk 0.40cvss 6.1epss 0.09

    Optergy Proton/Enterprise devices allow Open Redirect.

  • CVE-2019-13038MedJun 29, 2019
    risk 0.40cvss 6.1epss 0.01

    mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.

  • CVE-2017-14394MedJun 19, 2019
    risk 0.40cvss 6.1epss 0.01

    OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via an unvalidated redirect.

  • CVE-2019-3477MedJun 7, 2019
    risk 0.40cvss 6.1epss 0.01

    Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.

  • CVE-2019-4201MedJun 6, 2019
    risk 0.40cvss 6.1epss 0.01

    IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL…

  • CVE-2018-13384MedJun 4, 2019
    risk 0.40cvss 6.1epss 0.01

    A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

  • CVE-2019-5946MedMay 17, 2019
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the Login Screen.

  • CVE-2019-10117MedMay 16, 2019
    risk 0.40cvss 6.1epss 0.01

    An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

  • CVE-2019-8951MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.01

    An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote attacker to redirect users to an arbitrary URL. Affected hardware products: Bosch DIVAR IP 2000 (vulnerable versions: 3.10;…