CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Description
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-178
CVEs mapped to this weakness (1,767)
page 71 of 89| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-28628 | Med | 0.28 | 5.4 | 0.01 | Mar 27, 2023 | lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious URLs to be parsed by the `lambdaisland/uri` and return the wrong authority. This issue is similar to but distinct from… | ||
| CVE-2023-0681 | Med | 0.28 | 4.3 | 0.00 | Mar 20, 2023 | Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application.… | ||
| CVE-2022-3381 | Med | 0.28 | 4.3 | 0.01 | Mar 9, 2023 | An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites | ||
| CVE-2022-41273 | Med | 0.28 | 4.3 | 0.00 | Dec 13, 2022 | Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be… | ||
| CVE-2022-25295 | Med | 0.28 | 5.4 | 0.01 | Sep 11, 2022 | This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts… | ||
| CVE-2022-35406 | Med | 0.28 | 4.3 | 0.01 | Jul 8, 2022 | A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect. | ||
| CVE-2022-1209 | Med | 0.28 | 4.3 | 0.01 | May 10, 2022 | The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1. | ||
| CVE-2021-44054 | Med | 0.28 | 4.3 | 0.01 | May 5, 2022 | An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following… | ||
| CVE-2021-23495 | Med | 0.28 | 5.4 | 0.01 | Feb 25, 2022 | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter. | ||
| CVE-2021-43064 | Med | 0.28 | 4.3 | 0.01 | Dec 8, 2021 | A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers. | ||
| CVE-2021-3851 | Med | 0.28 | 5.4 | 0.01 | Oct 19, 2021 | firefly-iii is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-3664 | Med | 0.28 | 5.3 | 0.02 | Jul 26, 2021 | url-parse is vulnerable to URL Redirection to Untrusted Site | ||
| CVE-2021-23393 | Med | 0.28 | 5.4 | 0.01 | Jun 11, 2021 | This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only… | ||
| CVE-2021-23387 | Med | 0.28 | 5.4 | 0.01 | May 24, 2021 | The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web… | ||
| CVE-2021-23384 | Med | 0.28 | 5.4 | 0.01 | May 17, 2021 | The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in… | ||
| CVE-2020-1059 | Med | 0.28 | 4.3 | 0.02 | May 21, 2020 | A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content… | ||
| CVE-2019-14403 | Med | 0.28 | 4.3 | 0.01 | Jul 30, 2019 | cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). | ||
| CVE-2018-5304 | Med | 0.28 | 4.3 | 0.01 | May 11, 2018 | An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party… | ||
| CVE-2017-14725 | Med | 0.28 | 5.4 | 0.02 | Sep 23, 2017 | Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php. | ||
| CVE-2026-53654 | Med | 0.27 | — | 0.00 | Aug 19, 2026 | Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative Location target. Controller::execute()… |
- risk 0.28cvss 5.4epss 0.01
lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious URLs to be parsed by the `lambdaisland/uri` and return the wrong authority. This issue is similar to but distinct from…
- risk 0.28cvss 4.3epss 0.00
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application.…
- risk 0.28cvss 4.3epss 0.01
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
- risk 0.28cvss 4.3epss 0.00
Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be…
- risk 0.28cvss 5.4epss 0.01
This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts…
- risk 0.28cvss 4.3epss 0.01
A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or Intruder, it may be incorrectly interpreted as a redirect.
- risk 0.28cvss 4.3epss 0.01
The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied URLs in the social fields of the Profile Page, which makes it possible for attackers to redirect unsuspecting victims in versions up to, and including, 2.3.1.
- risk 0.28cvss 4.3epss 0.01
An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerability in the following…
- risk 0.28cvss 5.4epss 0.01
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
- risk 0.28cvss 4.3epss 0.01
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.
- risk 0.28cvss 5.4epss 0.01
firefly-iii is vulnerable to URL Redirection to Untrusted Site
- risk 0.28cvss 5.3epss 0.02
url-parse is vulnerable to URL Redirection to Untrusted Site
- risk 0.28cvss 5.4epss 0.01
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only…
- risk 0.28cvss 5.4epss 0.01
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web…
- risk 0.28cvss 5.4epss 0.01
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in…
- risk 0.28cvss 4.3epss 0.02
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially crafted website could either spoof content…
- risk 0.28cvss 4.3epss 0.01
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
- risk 0.28cvss 4.3epss 0.01
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party…
- risk 0.28cvss 5.4epss 0.02
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
- risk 0.27cvss —epss 0.00
Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an unauthenticated request to set an external http, https, or protocol-relative Location target. Controller::execute()…