CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,693)
page 44 of 85| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-22266 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22265 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22264 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22263 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22262 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22261 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22260 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22259 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22258 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22257 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-22256 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2023 | Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue… | ||
| CVE-2023-27292 | Med | 0.35 | 5.4 | 0.01 | Feb 28, 2023 | An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters. | ||
| CVE-2022-43721 | Med | 0.35 | 5.4 | 0.01 | Jan 16, 2023 | An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. | ||
| CVE-2021-23385 | Med | 0.35 | 5.4 | 0.01 | Aug 2, 2022 | This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This… | ||
| CVE-2020-25154 | Med | 0.35 | 5.4 | 0.01 | Apr 14, 2022 | An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites. | ||
| CVE-2022-27110 | Med | 0.35 | 5.4 | 0.00 | Apr 6, 2022 | OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint. | ||
| CVE-2022-27109 | Med | 0.35 | 5.4 | 0.00 | Apr 6, 2022 | OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability. | ||
| CVE-2022-26950 | Med | 0.35 | 5.4 | 0.01 | Mar 30, 2022 | Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently… | ||
| CVE-2005-10001 | Med | 0.35 | 5.4 | 0.01 | Mar 28, 2022 | A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been… | ||
| CVE-2022-27090 | Med | 0.35 | 5.4 | 0.00 | Mar 21, 2022 | Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter. |
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.00
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue…
- risk 0.35cvss 5.4epss 0.01
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.
- risk 0.35cvss 5.4epss 0.01
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0.
- risk 0.35cvss 5.4epss 0.01
This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This…
- risk 0.35cvss 5.4epss 0.01
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.
- risk 0.35cvss 5.4epss 0.00
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
- risk 0.35cvss 5.4epss 0.00
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
- risk 0.35cvss 5.4epss 0.01
Archer 6.x through 6.9 P2 (6.9.0.2) is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently…
- risk 0.35cvss 5.4epss 0.01
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redirect. The exploit has been…
- risk 0.35cvss 5.4epss 0.00
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.