VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 36 of 89
  • CVE-2018-7797MedDec 17, 2018
    risk 0.40cvss 6.1epss 0.01

    A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced…

  • CVE-2018-11067MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.02

    Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated…

  • CVE-2018-17948MedNov 20, 2018
    risk 0.40cvss 6.1epss 0.01

    An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.

  • CVE-2018-2476MedNov 13, 2018
    risk 0.40cvss 6.1epss 0.01

    Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.

  • CVE-2018-14658MedNov 13, 2018
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack

  • CVE-2018-13402MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.02

    Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version…

  • CVE-2018-13401MedOct 23, 2018
    risk 0.40cvss 6.1epss 0.02

    The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3,…

  • CVE-2018-12675MedOct 19, 2018
    risk 0.40cvss 6.1epss 0.04

    The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint.

  • CVE-2018-15493MedOct 17, 2018
    risk 0.40cvss 6.1epss 0.01

    vBulletin 5.4.3 has an Open Redirect.

  • CVE-2018-17870MedOct 1, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683.

  • CVE-2018-16954MedSep 18, 2018
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parameter is not validated by the application after a successful login. NOTE: this CVE…

  • CVE-2018-17074MedSep 16, 2018
    risk 0.40cvss 6.1epss 0.01

    The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.

  • CVE-2018-5548MedSep 13, 2018
    risk 0.40cvss 6.1epss 0.02

    On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.

  • CVE-2018-16761MedSep 9, 2018
    risk 0.40cvss 6.1epss 0.03

    Eventum before 3.4.0 has an open redirect vulnerability.

  • CVE-2018-14398MedSep 7, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.

  • CVE-2018-14366MedSep 6, 2018
    risk 0.40cvss 6.1epss 0.02

    download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.

  • CVE-2018-1000671MedSep 6, 2018
    risk 0.40cvss 6.1epss 0.05

    sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be…

  • CVE-2018-15683MedSep 5, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be instantly redirected.

  • CVE-2018-7692MedAug 9, 2018
    risk 0.40cvss 6.1epss 0.01

    Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.

  • CVE-2018-7091MedAug 6, 2018
    risk 0.40cvss 6.1epss 0.01

    HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.