VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,693)

page 44 of 85
  • CVE-2023-22266MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22265MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22264MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22263MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22262MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22261MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22260MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22259MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22258MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22257MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-22256MedMar 22, 2023
    risk 0.35cvss 5.4epss 0.00

    Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…

  • CVE-2023-27292MedFeb 28, 2023
    risk 0.35cvss 5.4epss 0.01

    An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.

  • CVE-2022-43721MedJan 16, 2023
    risk 0.35cvss 5.4epss 0.01

    An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.

  • CVE-2021-23385MedAug 2, 2022
    risk 0.35cvss 5.4epss 0.01

    This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This…

  • CVE-2020-25154MedApr 14, 2022
    risk 0.35cvss 5.4epss 0.01

    An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.

  • CVE-2022-27110MedApr 6, 2022
    risk 0.35cvss 5.4epss 0.00

    OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.

  • CVE-2022-27109MedApr 6, 2022
    risk 0.35cvss 5.4epss 0.00

    OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.

  • CVE-2022-26950MedMar 30, 2022
    risk 0.35cvss 5.4epss 0.01

    Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently…

  • CVE-2005-10001MedMar 28, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been…

  • CVE-2022-27090MedMar 21, 2022
    risk 0.35cvss 5.4epss 0.00

    Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.