CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 17 of 36
- CVE-2022-23184MEDIUMCVSS 6.1EG 6.12022-02-07
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
- CVE-2021-45408MEDIUMCVSS 6.1EG 6.12022-02-04
Open Redirect vulnerability exists in SeedDMS 6.0.15 in out.Login.php, which llows remote malicious users to redirect users to malicious sites using the "referuri" parameter.
- CVE-2022-22919MEDIUMCVSS 6.1EG 6.12022-01-30
Adenza AxiomSL ControllerView through 10.8.1 allows redirection for SSO login URLs.
- CVE-2021-25074MEDIUMCVSS 6.1EG 6.12022-01-24
The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue
- CVE-2021-25028MEDIUMCVSS 6.1EG 6.12022-01-24
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue
- CVE-2021-24838MEDIUMCVSS 6.1EG 6.12022-01-17
The AnyComment WordPress plugin before 0.3.5 has an API endpoint which passes user input via the redirect parameter to the wp_redirect() function without being validated first, leading to an Open Redirect issue, which according to the vend…
- CVE-2022-0235MEDIUMCVSS 6.1EG 6.12022-01-16
node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2021-38678MEDIUMCVSS 6.1EG 6.12022-01-14
An open redirect vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows attackers to redirect users to an untrusted page that contains malware. We have already fixed this vulnerabil…
- CVE-2021-44528MEDIUMCVSS 6.1EG 6.12022-01-10
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack t…
- CVE-2022-0122MEDIUMCVSS 6.1EG 6.12022-01-06
forge is vulnerable to URL Redirection to Untrusted Site
- CVE-2021-20875MEDIUMCVSS 6.1EG 6.12021-12-24
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary we…
- CVE-2021-40852MEDIUMCVSS 6.1EG 6.12021-12-17
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain infor…
- CVE-2020-18985MEDIUMCVSS 6.1EG 6.12021-12-15
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
- CVE-2021-3829MEDIUMCVSS 6.1EG 6.12021-12-10
openwhyd is vulnerable to URL Redirection to Untrusted Site
- CVE-2021-43532MEDIUMCVSS 6.1EG 6.12021-12-08
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the mid…
- CVE-2021-3989MEDIUMCVSS 6.1EG 6.12021-12-01
showdoc is vulnerable to URL Redirection to Untrusted Site
- CVE-2021-41733MEDIUMCVSS 6.1EG 6.12021-11-08
Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
- CVE-2021-43058MEDIUMCVSS 6.1EG 6.12021-11-01
An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exploit this vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click …
- CVE-2021-34764MEDIUMCVSS 6.1EG 6.12021-10-27
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information abou…
- CVE-2021-22942MEDIUMCVSS 6.1EG 6.12021-10-18
A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow attackers to redirect users to a malicious website.
- CVE-2021-22963MEDIUMCVSS 6.1EG 6.12021-10-14
A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up o…
- CVE-2021-20806MEDIUMCVSS 6.1EG 6.12021-10-13
Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2021-20031MEDIUMCVSS 6.1EG 6.12021-10-12
A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.
- CVE-2021-41826MEDIUMCVSS 6.1EG 6.12021-09-30
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
- CVE-2021-23052MEDIUMCVSS 6.1EG 6.12021-09-14
On version 14.1.x before 14.1.4.4 and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This vulnerability allows an unauthenticated malicious user to build an open re…
- CVE-2021-39501MEDIUMCVSS 6.1EG 6.12021-09-07
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
- CVE-2021-38123MEDIUMCVSS 6.1EG 6.12021-09-07
Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018.05, 2018.11, 2019.05, 2020.02, 2020.08, 2020.11, 2021.05. The vulnerability could allow redirect users to malicious web…
- CVE-2021-37352MEDIUMCVSS 6.1EG 6.12021-08-13
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
- CVE-2021-22098MEDIUMCVSS 6.1EG 6.12021-08-11
UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along wit…
- CVE-2021-33707MEDIUMCVSS 6.1EG 6.12021-08-10
SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and in…
- CVE-2021-33331MEDIUMCVSS 6.1EG 6.12021-08-03
Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary…
- CVE-2021-21579MEDIUMCVSS 6.1EG 6.12021-08-03
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciou…
- CVE-2021-21578MEDIUMCVSS 6.1EG 6.12021-08-03
Dell EMC iDRAC9 versions prior to 4.40.40.00 contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on maliciou…
- CVE-2021-37746MEDIUMCVSS 6.1EG 6.12021-07-30
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
- CVE-2021-20789MEDIUMCVSS 6.1EG 6.12021-07-30
Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version …
- CVE-2020-5329MEDIUMCVSS 6.1EG 6.12021-07-29
Dell EMC Avamar Server contains an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously craft…
- CVE-2021-35966MEDIUMCVSS 6.1EG 6.12021-07-19
The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL can be redirected to any website. Remote attackers can use the vulnerability to execute phishing attacks.
- CVE-2021-3647MEDIUMCVSS 6.1EG 6.12021-07-16
URI.js is vulnerable to URL Redirection to Untrusted Site
- CVE-2021-35037MEDIUMCVSS 6.1EG 6.12021-07-12
Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their environments on-premises. An attacker may craft a URL that appears to be for a customer's Jamf Pro instance, but when …
- CVE-2021-24406MEDIUMCVSS 6.1EG 6.12021-07-06
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to us…
- CVE-2021-34807MEDIUMCVSS 6.1EG 6.12021-07-02
An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the vulnerability, an attacker would need to have obtained a valid zimbra auth token or a valid preauth token. Once the tok…
- CVE-2021-20105MEDIUMCVSS 6.1EG 6.12021-06-29
Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' parameter.
- CVE-2021-34254MEDIUMCVSS 6.1EG 6.12021-06-28
Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
- CVE-2020-18660MEDIUMCVSS 6.1EG 6.12021-06-23
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
- CVE-2021-35206MEDIUMCVSS 6.1EG 6.12021-06-22
Gitpod before 0.6.0 allows unvalidated redirects.
- CVE-2010-4266MEDIUMCVSS 6.1EG 6.12021-06-22
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
- CVE-2021-20733MEDIUMCVSS 6.1EG 6.12021-06-22
Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the v…
- CVE-2021-32956MEDIUMCVSS 6.1EG 6.12021-06-18
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.
- CVE-2021-24358MEDIUMCVSS 6.1EG 6.12021-06-14
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.
- CVE-2021-22903MEDIUMCVSS 6.1EG 6.12021-06-11
The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to red…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →