CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 16 of 36
- CVE-2022-40754MEDIUMCVSS 6.1EG 6.12022-09-21
In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
- CVE-2022-31735MEDIUMCVSS 6.1EG 6.12022-09-15
OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601). When accessing an affected server through some specially crafted URL, the user may be redirected to an arbitrary webs…
- CVE-2022-39814MEDIUMCVSS 6.1EG 6.12022-09-13
In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
- CVE-2022-38131MEDIUMCVSS 6.1EG 6.12022-09-06
RStudio Connect prior to 2023.01.0 is affected by an Open Redirect issue. The vulnerability could allow an attacker to redirect users to malicious websites.
- CVE-2021-29864MEDIUMCVSS 6.1EG 6.12022-08-30
IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulner…
- CVE-2021-3639MEDIUMCVSS 6.1EG 6.12022-08-22
A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an …
- CVE-2022-25799MEDIUMCVSS 6.1EG 6.12022-08-16
An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authen…
- CVE-2022-27509MEDIUMCVSS 6.1EG 6.12022-07-28
Unauthenticated redirection to a malicious website
- CVE-2022-30706MEDIUMCVSS 6.1EG 6.12022-07-26
Open redirect vulnerability in Booked versions prior to 3.3 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- CVE-2022-35652MEDIUMCVSS 6.1EG 6.12022-07-25
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victim…
- CVE-2022-25803MEDIUMCVSS 6.1EG 6.12022-07-14
Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
- CVE-2022-2252MEDIUMCVSS 6.1EG 6.12022-06-29
Open Redirect in GitHub repository microweber/microweber prior to 1.2.19.
- CVE-2020-26877MEDIUMCVSS 6.1EG 6.12022-06-29
ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to the redirect URI submitted with the aut…
- CVE-2022-29272MEDIUMCVSS 6.1EG 6.12022-06-29
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
- CVE-2022-33146MEDIUMCVSS 6.1EG 6.12022-06-27
Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- CVE-2022-32444MEDIUMCVSS 6.1EG 6.12022-06-17
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.
- CVE-2022-24969MEDIUMCVSS 6.1EG 6.12022-06-09
bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability.
- CVE-2022-29718MEDIUMCVSS 6.1EG 6.12022-06-02
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
- CVE-2022-23237MEDIUMCVSS 6.1EG 6.12022-06-02
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.
- CVE-2022-29214MEDIUMCVSS 6.1EG 6.12022-05-21
NextAuth.js (next-auth) is am open source authentication solution for Next.js applications. Prior to versions 3.29.3 and 4.3.3, an open redirect vulnerability is present when the developer is implementing an OAuth 1 provider. Versions 3.29…
- CVE-2022-1774MEDIUMCVSS 6.1EG 6.12022-05-18
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
- CVE-2022-30992MEDIUMCVSS 6.1EG 6.12022-05-18
Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
- CVE-2022-1702MEDIUMCVSS 6.1EG 6.12022-05-13
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site and uses that link in a redirect which leads to Open redirection vulnerability.
- CVE-2022-27461MEDIUMCVSS 6.1EG 6.12022-05-04
In nopCommerce 4.50.1, an open redirect vulnerability can be triggered by luring a user to authenticate to a nopCommerce page by clicking on a crafted link.
- CVE-2021-25111MEDIUMCVSS 6.1EG 6.12022-04-25
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
- CVE-2020-14118MEDIUMCVSS 6.1EG 6.12022-04-21
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps.
- CVE-2022-1254MEDIUMCVSS 6.1EG 6.12022-04-20
A URL redirection vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.9, 9.x prior to 9.2.20, 8.x prior to 8.2.27, and 7.x prior to 7.8.2.31, and controlled release 11.x prior to 11.1.3 allows a remote attacker to redirect a u…
- CVE-2022-24858MEDIUMCVSS 6.1EG 6.12022-04-19
next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability. If you are not able to upgrade for any reason, you can add…
- CVE-2022-0645MEDIUMCVSS 6.1EG 6.12022-04-19
Open redirect vulnerability via endpoint authorize_and_redirect/?redirect= in GitHub repository posthog/posthog prior to 1.34.1.
- CVE-2022-27256MEDIUMCVSS 6.1EG 6.12022-04-13
A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
- CVE-2022-27463MEDIUMCVSS 6.1EG 6.12022-04-05
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
- CVE-2022-1233MEDIUMCVSS 6.1EG 6.12022-04-04
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
- CVE-2022-23798MEDIUMCVSS 6.1EG 6.12022-03-30
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not.
- CVE-2022-24776MEDIUMCVSS 6.1EG 6.12022-03-24
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue i…
- CVE-2021-32478MEDIUMCVSS 6.1EG 6.12022-03-11
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
- CVE-2022-0697MEDIUMCVSS 6.1EG 6.12022-03-06
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0.
- CVE-2022-0868MEDIUMCVSS 6.1EG 6.12022-03-06
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
- CVE-2022-0869MEDIUMCVSS 6.1EG 6.12022-03-06
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3.
- CVE-2021-46379MEDIUMCVSS 6.1EG 6.12022-03-04
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site.
- CVE-2021-3654MEDIUMCVSS 6.1EG 6.12022-03-02
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
- CVE-2022-26158MEDIUMCVSS 6.1EG 6.12022-02-28
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host: header of the HTT…
- CVE-2022-26156MEDIUMCVSS 6.1EG 6.12022-02-28
An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form action. Form-action…
- CVE-2022-24330MEDIUMCVSS 6.1EG 6.12022-02-25
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
- CVE-2021-29217MEDIUMCVSS 6.1EG 6.12022-02-24
A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard.
- CVE-2022-0692MEDIUMCVSS 6.1EG 6.12022-02-21
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1.
- CVE-2022-0597MEDIUMCVSS 6.1EG 6.12022-02-15
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
- CVE-2021-25033MEDIUMCVSS 6.1EG 6.12022-02-14
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
- CVE-2022-0560MEDIUMCVSS 6.1EG 6.12022-02-11
Open Redirect in Packagist microweber/microweber prior to 1.2.11.
- CVE-2022-23102MEDIUMCVSS 6.1EG 6.12022-02-09
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Affected products contain an open redirect vulnerability. An attacker could trick a valid authenticated user to the device into clicking a malicious…
- CVE-2021-45328MEDIUMCVSS 6.1EG 6.12022-02-08
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →