VYPR

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

BaseDraftLikelihood: Low

Description

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-178

CVEs mapped to this weakness (1,767)

page 70 of 89
  • CVE-2025-0705MedJan 24, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this vulnerability is the function qrCode of the file src/main/java/io/github/controller/QrCodeController.java. The manipulation of the…

  • CVE-2024-12990MedDec 27, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown part of the file /user/admin-verify of the component Admin Verification Page. The manipulation of the argument nexturl with the input…

  • CVE-2024-38485MedDec 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.

  • CVE-2024-11207MedNov 14, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit…

  • CVE-2024-8555MedSep 7, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file congratulations.php. The manipulation of the argument goto_page leads to open redirect. It is possible to launch…

  • CVE-2024-7941MedAug 27, 2024
    risk 0.28cvss 4.3epss 0.00

    An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

  • CVE-2024-7902MedAug 17, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be…

  • CVE-2024-21684MedJul 24, 2024
    risk 0.28cvss 4.3epss 0.00

    There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.2. This open redirect vulnerability,…

  • CVE-2024-37881MedJun 19, 2024
    risk 0.28cvss 5.3epss 0.01

    SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. However, SiteGuard WP Plugin versions prior to 1.7.7 missed to implement a measure to avoid redirection from…

  • CVE-2024-22244MedJun 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Open Redirect in Harbor  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.

  • CVE-2024-36406MedJun 10, 2024
    risk 0.28cvss 5.4epss 0.00

    SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows for open re-direct. Versions 7.14.4 and 8.6.1 contain a fix for this issue.

  • CVE-2024-27592MedApr 11, 2024
    risk 0.28cvss 4.3epss 0.01

    Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.

  • CVE-2024-28239MedMar 12, 2024
    risk 0.28cvss 5.4epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as an open redirect vulnerability as the user tries to log in via the API URL. There's a redirect that is done after…

  • CVE-2024-21723MedFeb 29, 2024
    risk 0.28cvss 4.3epss 0.01

    Inadequate parsing of URLs could result into an open redirect.

  • CVE-2024-24763MedFeb 20, 2024
    risk 0.28cvss 4.3epss 0.01

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facilitating phishing attacks or cross-site…

  • CVE-2023-50704MedDec 20, 2023
    risk 0.28cvss 4.3epss 0.00

    An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.

  • CVE-2023-47168MedNov 27, 2023
    risk 0.28cvss 4.3epss 0.00

    Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=

  • CVE-2023-32068MedMay 15, 2023
    risk 0.28cvss 4.7epss 0.55

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerability was partially fixed in…

  • CVE-2022-43950MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.00

    A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any…

  • CVE-2023-22729MedApr 26, 2023
    risk 0.28cvss 5.4epss 0.00

    Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legitimate content author to follow a…