CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,682 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 1 of 34
- CVE-2004-2260MEDIUMCVSS v2 5.0EG 5.02004-12-31
Opera Browser 7.23, and other versions before 7.50, updates the address bar as soon as the user clicks a link, which allows remote attackers to redirect to other sites via the onUnload attribute.
- CVE-2005-0420MEDIUMCVSS v2 5.8EG 5.82005-04-27
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.
- CVE-2005-10001MEDIUMCVSS 5.4EG 6.12022-03-28
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads t…
- CVE-2005-1475HIGHCVSS v2 7.5EG 7.52005-06-16
The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.
- CVE-2005-4206MEDIUMCVSS 6.1EG 6.12005-12-13
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to framese…
- CVE-2008-1547MEDIUMCVSS v2 4.3EG 4.32008-10-21
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via …
- CVE-2008-2052MEDIUMCVSS 6.1EG 6.12008-05-02
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.
- CVE-2009-3832MEDIUMCVSS v2 5.8EG 5.82009-10-30
Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site.
- CVE-2010-2471MEDIUMCVSS 6.1EG 6.12019-11-06
Drupal versions 5.x and 6.x has open redirection
- CVE-2010-3661MEDIUMCVSS 6.1EG 6.12019-11-01
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
- CVE-2010-3669MEDIUMCVSS 5.4EG 5.42019-11-04
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
- CVE-2010-4266MEDIUMCVSS 6.1EG 6.12021-06-22
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
- CVE-2011-1594MEDIUMCVSS 6.5EG 6.52014-02-05
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attac…
- CVE-2012-0518CRITICALCVSS 4.7EG 9.0⚠ KEV2012-10-16
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than…
- CVE-2013-0594MEDIUMCVSS 6.1EG 6.12018-07-11
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.
- CVE-2013-2621MEDIUMCVSS 6.1EG 6.12020-02-03
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
- CVE-2013-2764MEDIUMCVSS 6.1EG 6.12020-01-28
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
- CVE-2014-2213MEDIUMCVSS 6.1EG 6.12019-11-22
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendm…
- CVE-2014-3652MEDIUMCVSS 6.1EG 6.12019-12-15
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
- CVE-2014-9617MEDIUMCVSS 6.1EG 6.12020-02-19
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
- CVE-2015-10052MEDIUMCVSS 4.6EG 6.12023-01-15
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in calesanz gibb-modul-151. This affects the function bearbeiten/login. The manipulation leads to open redirect. It is possible to initiate the…
- CVE-2015-10102MEDIUMCVSS 6.3EG 6.32023-04-17
A vulnerability, which was classified as critical, has been found in Freshdesk Plugin 1.7 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to open redirect. The attack may be launched remotely. Upg…
- CVE-2015-10104LOWCVSS 3.5EG 3.52023-04-30
A vulnerability, which was classified as problematic, has been found in Icons for Features Plugin 1.0.0 on WordPress. Affected by this issue is some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipula…
- CVE-2015-10112MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability classified as problematic has been found in WooFramework Branding Plugin up to 1.0.1 on WordPress. Affected is the function admin_screen_logic of the file wooframework-branding.php. The manipulation of the argument url lead…
- CVE-2015-10113LOWCVSS 3.5EG 3.52023-06-05
A vulnerability classified as problematic was found in WooFramework Tweaks Plugin up to 1.0.1 on WordPress. Affected by this vulnerability is the function admin_screen_logic of the file wooframework-tweaks.php. The manipulation of the argu…
- CVE-2015-10114MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipul…
- CVE-2015-10115MEDIUMCVSS 4.3EG 4.32023-06-05
A vulnerability, which was classified as problematic, was found in WooSidebars Sidebar Manager Converter Plugin up to 1.1.1 on WordPress. This affects the function process_request of the file classes/class-woosidebars-sbm-converter.php. Th…
- CVE-2015-2749MEDIUMCVSS 6.1EG 6.12017-09-13
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
- CVE-2015-2750MEDIUMCVSS 6.1EG 6.12017-09-13
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial seq…
- CVE-2015-3190MEDIUMCVSS 6.1EG 6.12017-05-25
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to …
- CVE-2015-3880MEDIUMCVSS 6.1EG 6.12017-09-19
Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2015-3898MEDIUMCVSS 6.1EG 6.12018-02-28
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp o…
- CVE-2015-4070MEDIUMCVSS 6.1EG 6.12017-05-17
Open redirect vulnerability in the proxyimages function in wowproxy.php in the Wow Moodboard Lite plugin 1.1.1.1 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u…
- CVE-2015-4668MEDIUMCVSS 6.1EG 6.12017-09-25
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
- CVE-2015-5054MEDIUMCVSS 6.1EG 6.12017-09-11
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
- CVE-2015-5241MEDIUMCVSS 6.1EG 6.12017-05-19
After logging into the portal, the logout jsp page redirects the browser back to the login page after. It is feasible for malicious users to redirect the browser to an unintended web page in Apache jUDDI 3.1.2, 3.1.3, 3.1.4, and 3.1.5 when…
- CVE-2015-5608MEDIUMCVSS 6.1EG 6.12017-09-20
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
- CVE-2015-6501MEDIUMCVSS 6.1EG 6.12017-01-12
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.
- CVE-2015-6961MEDIUMCVSS 6.1EG 6.12017-10-18
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the _next parameter to user/logout.
- CVE-2015-7943MEDIUMCVSS 6.1EG 6.12017-10-18
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web…
- CVE-2015-8094MEDIUMCVSS 6.1EG 6.12018-05-22
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
- CVE-2015-9058MEDIUMCVSS 6.1EG 6.12017-05-03
Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.
- CVE-2015-9540MEDIUMCVSS 6.1EG 6.12020-01-04
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
- CVE-2016-0204MEDIUMCVSS 6.8EG 6.82016-10-16
Open redirect vulnerability in IBM Cloud Orchestrator 2.4.x before 2.4.0 FP3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2016-0228MEDIUMCVSS 5.4EG 5.42017-04-17
IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. I…
- CVE-2016-0329MEDIUMCVSS 5.4EG 5.42018-02-02
Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10.0.2.x before 10.0.2.8_iFix1, 10.0.4.0 before 10.0.4.0_iFix8, and 10.1.0.0 before 10.1.0.0_iFix3 allows remote attackers…
- CVE-2016-0928HIGHCVSS 7.4EG 7.42016-09-18
Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2016-1000001HIGHCVSS 7.4EG 7.42016-10-07
flask-oidc version 0.1.2 and earlier is vulnerable to an open redirect
- CVE-2016-1000107MEDIUMCVSS 6.1EG 6.12019-12-10
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to …
- CVE-2016-1000108MEDIUMCVSS 6.1EG 6.12019-12-10
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow …
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →