VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,692)

page 67 of 85
  • CVE-2024-21723MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.01

    Inadequate parsing of URLs could result into an open redirect.

  • CVE-2024-24763MedFeb 20, 2024
    risk 0.28cvss 4.3epss 0.01

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facilitating phishing attacks or cross-site…

  • CVE-2023-50704MedDec 20, 2023
    risk 0.28cvss 4.3epss 0.00

    An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.

  • CVE-2023-47168MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=

  • CVE-2023-32068MedMay 15, 2023
    risk 0.28cvss 4.7epss 0.55

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerability was partially fixed in…

  • CVE-2022-43950MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.00

    A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any…

  • CVE-2023-22729MedApr 26, 2023
    risk 0.28cvss 5.4epss 0.00

    Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a…

  • CVE-2023-28628MedMar 27, 2023
    risk 0.28cvss 5.4epss 0.01

    lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious URLs to be parsed by the `lambdaisland/uri` and return the wrong authority. This issue is similar to but distinct from…

  • CVE-2023-0681MedMar 20, 2023
    risk 0.28cvss 4.3epss 0.00

    Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application.…

  • CVE-2022-3381MedMar 9, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites

  • CVE-2022-41273MedDec 13, 2022
    risk 0.28cvss 4.3epss 0.00

    Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be…

  • CVE-2022-25295MedSep 11, 2022
    risk 0.28cvss 5.4epss 0.01

    This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts…

  • CVE-2022-35406MedJul 8, 2022
    risk 0.28cvss 4.3epss 0.01

    A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.

  • CVE-2022-1209MedMay 10, 2022
    risk 0.28cvss 4.3epss 0.01

    The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.

  • CVE-2021-44054MedMay 5, 2022
    risk 0.28cvss 4.3epss 0.01

    An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following…

  • CVE-2021-23495MedFeb 25, 2022
    risk 0.28cvss 5.4epss 0.01

    The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.

  • CVE-2021-43064MedDec 8, 2021
    risk 0.28cvss 4.3epss 0.01

    A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.

  • CVE-2021-3851MedOct 19, 2021
    risk 0.28cvss 5.4epss 0.01

    firefly-iii is vulnerable to URL Redirection to Untrusted Site

  • CVE-2021-3664MedJul 26, 2021
    risk 0.28cvss 5.3epss 0.02

    url-parse is vulnerable to URL Redirection to Untrusted Site

  • CVE-2021-23393MedJun 11, 2021
    risk 0.28cvss 5.4epss 0.01

    This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only…