VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,693)

page 43 of 85
  • CVE-2025-0244MedJan 7, 2025
    risk 0.35cvss 5.3epss 0.07

    When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.

  • CVE-2024-55452MedDec 16, 2024
    risk 0.35cvss 5.4epss 0.00

    A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When…

  • CVE-2024-30140MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.

  • CVE-2024-4612MedSep 12, 2024
    risk 0.35cvss 6.4epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

  • CVE-2024-4445MedMay 14, 2024
    risk 0.35cvss 6.5epss 0.00

    The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the several functions in versions up to, and including, 6.20.01. This makes it possible for authenticated attackers, with…

  • CVE-2024-1183MedApr 16, 2024
    risk 0.35cvss 6.5epss 0.02

    An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal…

  • CVE-2024-25657MedMar 18, 2024
    risk 0.35cvss 5.4epss 0.00

    An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to redirect authenticated users to malicious websites.

  • CVE-2022-45169MedFeb 21, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other…

  • CVE-2024-21497MedFeb 17, 2024
    risk 0.35cvss 5.4epss 0.01

    Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit…

  • CVE-2024-21794MedFeb 2, 2024
    risk 0.35cvss 5.4epss 0.00

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.

  • CVE-2024-0854MedJan 24, 2024
    risk 0.35cvss 5.4epss 0.00

    URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified…

  • CVE-2024-0319MedJan 15, 2024
    risk 0.35cvss 5.4epss 0.00

    Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious page by changing the 'redirect_uri' parameter.

  • CVE-2024-21641MedJan 5, 2024
    risk 0.35cvss 6.5epss 0.01

    Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redirect parameter that allows any third party to redirect users from a (trusted) domain of the Flarum installation to redirect to any link. For logged-in users, the…

  • CVE-2023-5610MedNov 20, 2023
    risk 0.35cvss 5.4epss 0.00

    The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect

  • CVE-2023-5445MedNov 17, 2023
    risk 0.35cvss 5.4epss 0.00

    An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashboard area of the user interface. A user…

  • CVE-2023-23957MedSep 19, 2023
    risk 0.35cvss 5.4epss 0.00

    An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4

  • CVE-2023-29307MedJun 15, 2023
    risk 0.35cvss 5.4epss 0.01

    Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this…

  • CVE-2022-4946MedJun 5, 2023
    risk 0.35cvss 5.4epss 0.00

    The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.

  • CVE-2023-0155MedMay 3, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown

  • CVE-2023-2000MedMay 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website