CWE-601— URL Redirection to Untrusted Site (Open Redirect)
976 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 1 of 20
- CVE-2005-10001MEDIUMCVSS 5.4EG 6.12022-03-28
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads t…
- CVE-2010-2471MEDIUMCVSS 6.1EG 6.12019-11-06
Drupal versions 5.x and 6.x has open redirection
- CVE-2010-3661MEDIUMCVSS 6.1EG 6.12019-11-01
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
- CVE-2010-3669MEDIUMCVSS 5.4EG 5.42019-11-04
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
- CVE-2010-4266MEDIUMCVSS 6.1EG 6.12021-06-22
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
- CVE-2013-0594MEDIUMCVSS 6.12018-07-11
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.
- CVE-2013-2621MEDIUMCVSS 6.1EG 6.12020-02-03
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
- CVE-2013-2764MEDIUMCVSS 6.1EG 6.12020-01-28
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
- CVE-2014-2213MEDIUMCVSS 6.1EG 6.12019-11-22
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendm…
- CVE-2014-3652MEDIUMCVSS 6.1EG 6.12019-12-15
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
- CVE-2014-9617MEDIUMCVSS 6.1EG 6.12020-02-19
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
- CVE-2015-10052MEDIUMCVSS 4.6EG 6.12023-01-15
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in calesanz gibb-modul-151. This affects the function bearbeiten/login. The manipulation leads to open redirect. It is possible to initiate the…
- CVE-2015-10102MEDIUMCVSS 6.3EG 6.32023-04-17
A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to open redirect. The attack may be launched remotely. Upg…
- CVE-2015-10104LOWCVSS 3.5EG 3.52023-04-30
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipula…
- CVE-2015-10112MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url lead…
- CVE-2015-10113LOWCVSS 3.5EG 3.52023-06-05
A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manipulation of the argu…
- CVE-2015-10114MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipul…
- CVE-2015-10115MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sbm-converter.php. Th…
- CVE-2015-3898MEDIUMCVSS 6.12018-02-28
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp o…
- CVE-2015-8094MEDIUMCVSS 6.12018-05-22
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
- CVE-2015-9540MEDIUMCVSS 6.1EG 6.12020-01-04
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
- CVE-2016-0329MEDIUMCVSS 5.42018-02-02
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers…
- CVE-2016-1000107MEDIUMCVSS 6.1EG 6.12019-12-10
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to …
- CVE-2016-1000108MEDIUMCVSS 6.1EG 6.12019-12-10
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow …
- CVE-2016-1000110MEDIUMCVSS 6.1EG 6.12019-11-27
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
- CVE-2016-10742MEDIUMCVSS 6.12019-02-17
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
- CVE-2016-10769MEDIUMCVSS 6.1EG 6.12019-08-05
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
- CVE-2016-15030LOWCVSS 3.5EG 6.12023-03-25
A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manipulation of the argument from leads to open redirect. It is possible to initiate the attack…
- CVE-2016-6154MEDIUMCVSS 6.1EG 6.12019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
- CVE-2016-9078HIGHCVSS 8.82018-06-11
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross…
- CVE-2017-0363MEDIUMCVSS 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
- CVE-2017-0364MEDIUMCVSS 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
- CVE-2017-1000434MEDIUMCVSS 6.12018-01-02
Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attacker controlled page classes/Furigana.php: header('location:'.urldecode($_GET['furikake-red…
- CVE-2017-1000481MEDIUMCVSS 6.12018-01-03
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might t…
- CVE-2017-1000484MEDIUMCVSS 6.12018-01-03
By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination wi…
- CVE-2017-14394MEDIUMCVSS 6.1EG 6.12019-06-19
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via …
- CVE-2017-14802MEDIUMCVSS 5.42018-03-02
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
- CVE-2017-1534MEDIUMCVSS 6.12018-01-10
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit t…
- CVE-2017-15419MEDIUMCVSS 6.52018-08-28
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
- CVE-2017-16224MEDIUMCVSS 6.12018-06-07
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to…
- CVE-2017-16652MEDIUMCVSS 6.12018-06-13
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path par…
- CVE-2017-1668MEDIUMCVSS 6.12018-01-09
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this…
- CVE-2017-1748MEDIUMCVSS 6.82018-06-04
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to…
- CVE-2017-18109MEDIUMCVSS 6.12019-03-29
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack v…
- CVE-2017-18178MEDIUMCVSS 6.12018-02-12
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
- CVE-2017-18262MEDIUMCVSS 6.12018-04-30
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/s…
- CVE-2017-18414HIGHCVSS 7.4EG 7.42019-08-02
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
- CVE-2017-18441MEDIUMCVSS 5.0EG 5.02019-08-02
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
- CVE-2017-18891MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
- CVE-2017-18897MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →