CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 36 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-7797 | Med | 0.40 | 6.1 | 0.01 | Dec 17, 2018 | A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced… | ||
| CVE-2018-11067 | Med | 0.40 | 6.1 | 0.02 | Nov 26, 2018 | Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated… | ||
| CVE-2018-17948 | Med | 0.40 | 6.1 | 0.01 | Nov 20, 2018 | An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3. | ||
| CVE-2018-2476 | Med | 0.40 | 6.1 | 0.01 | Nov 13, 2018 | Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site. | ||
| CVE-2018-14658 | Med | 0.40 | 6.1 | 0.01 | Nov 13, 2018 | A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack | ||
| CVE-2018-13402 | Med | 0.40 | 6.1 | 0.02 | Oct 23, 2018 | Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version… | ||
| CVE-2018-13401 | Med | 0.40 | 6.1 | 0.02 | Oct 23, 2018 | The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3,… | ||
| CVE-2018-12675 | — | Med | 0.40 | 6.1 | 0.04 | Oct 19, 2018 | The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint. | |
| CVE-2018-15493 | Med | 0.40 | 6.1 | 0.01 | Oct 17, 2018 | vBulletin 5.4.3 has an Open Redirect. | ||
| CVE-2018-17870 | Med | 0.40 | 6.1 | 0.01 | Oct 1, 2018 | An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683. | ||
| CVE-2018-16954 | Med | 0.40 | 6.1 | 0.02 | Sep 18, 2018 | An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parameter is not validated by the application after a successful login. NOTE: this CVE… | ||
| CVE-2018-17074 | Med | 0.40 | 6.1 | 0.01 | Sep 16, 2018 | The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. | ||
| CVE-2018-5548 | Med | 0.40 | 6.1 | 0.02 | Sep 13, 2018 | On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts. | ||
| CVE-2018-16761 | Med | 0.40 | 6.1 | 0.03 | Sep 9, 2018 | Eventum before 3.4.0 has an open redirect vulnerability. | ||
| CVE-2018-14398 | Med | 0.40 | 6.1 | 0.01 | Sep 7, 2018 | An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials. | ||
| CVE-2018-14366 | Med | 0.40 | 6.1 | 0.02 | Sep 6, 2018 | download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability. | ||
| CVE-2018-1000671 | Med | 0.40 | 6.1 | 0.05 | Sep 6, 2018 | sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be… | ||
| CVE-2018-15683 | Med | 0.40 | 6.1 | 0.01 | Sep 5, 2018 | An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be instantly redirected. | ||
| CVE-2018-7692 | Med | 0.40 | 6.1 | 0.01 | Aug 9, 2018 | Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1. | ||
| CVE-2018-7091 | Med | 0.40 | 6.1 | 0.01 | Aug 6, 2018 | HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr. |
- risk 0.40cvss 6.1epss 0.01
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced…
- risk 0.40cvss 6.1epss 0.02
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection vulnerability. A remote unauthenticated…
- risk 0.40cvss 6.1epss 0.01
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
- risk 0.40cvss 6.1epss 0.01
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
- risk 0.40cvss 6.1epss 0.01
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
- risk 0.40cvss 6.1epss 0.02
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3, from version…
- risk 0.40cvss 6.1epss 0.02
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.0 before version 7.11.3,…
- risk 0.40cvss 6.1epss 0.04
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint.
- risk 0.40cvss 6.1epss 0.01
vBulletin 5.4.3 has an Open Redirect.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parameter is not validated by the application after a successful login. NOTE: this CVE…
- risk 0.40cvss 6.1epss 0.01
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
- risk 0.40cvss 6.1epss 0.02
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using different blocks of cipher texts.
- risk 0.40cvss 6.1epss 0.03
Eventum before 3.4.0 has an open redirect vulnerability.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.
- risk 0.40cvss 6.1epss 0.02
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
- risk 0.40cvss 6.1epss 0.05
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be…
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be instantly redirected.
- risk 0.40cvss 6.1epss 0.01
Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.
- risk 0.40cvss 6.1epss 0.01
HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.