VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 47 of 89
  • CVE-2021-23401MedJul 5, 2021
    risk 0.35cvss 5.4epss 0.01

    This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only…

  • CVE-2020-23182MedJul 2, 2021
    risk 0.35cvss 5.4epss 0.01

    The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.

  • CVE-2021-27352MedMar 29, 2021
    risk 0.35cvss 5.4epss 0.01

    An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.

  • CVE-2021-1218MedJan 20, 2021
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the web management interface of Cisco Smart Software Manager satellite could allow an authenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request…

  • CVE-2020-10775MedAug 24, 2020
    risk 0.35cvss 5.3epss 0.02

    An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in their browser, the critical part of the URL…

  • CVE-2020-6266MedJun 10, 2020
    risk 0.35cvss 5.4epss 0.01

    SAP Fiori for SAP S/4HANA, versions - 100, 200, 300, 400, allows an attacker to redirect users to a malicious site due to insufficient URL validation, leading to URL Redirection.

  • CVE-2020-1997MedMay 13, 2020
    risk 0.35cvss 5.3epss 0.01

    An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenticates it will cause them to access an…

  • CVE-2019-17151MedJan 7, 2020
    risk 0.35cvss 5.4epss 0.01

    This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to exploit this vulnerability in that the target must be within a chat session together with the attacker.…

  • CVE-2010-3669MedNov 4, 2019
    risk 0.35cvss 5.4epss 0.01

    TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.

  • CVE-2019-5823MedJun 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2017-5871MedMay 22, 2019
    risk 0.35cvss 5.4epss 0.04

    Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).

  • CVE-2019-5433MedMay 6, 2019
    risk 0.35cvss 5.4epss 0.01

    A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially used for stealing credentials or other phishing attacks.…

  • CVE-2019-4035MedMar 22, 2019
    risk 0.35cvss 5.4epss 0.01

    IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IBM Content Navigator site, they can send a link to ICN users to send request to their Edit client directly. Then Edit client will download documents from the…

  • CVE-2018-15403MedOct 5, 2018
    risk 0.35cvss 5.4epss 0.02

    A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web…

  • CVE-2017-14802MedMar 2, 2018
    risk 0.35cvss 5.4epss 0.01

    Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.

  • CVE-2016-0329MedFeb 2, 2018
    risk 0.35cvss 5.4epss 0.01

    Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers to redirect users to arbitrary web…

  • CVE-2017-1449MedAug 31, 2017
    risk 0.35cvss 5.4epss 0.01

    IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a…

  • CVE-2017-1448MedAug 9, 2017
    risk 0.35cvss 5.4epss 0.01

    IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the…

  • CVE-2016-8949MedAug 9, 2017
    risk 0.35cvss 5.4epss 0.01

    IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the…

  • CVE-2017-11725MedJul 29, 2017
    risk 0.35cvss 5.4epss 0.01

    The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.