CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 18 of 36
- CVE-2020-18268MEDIUMCVSS 6.1EG 6.12021-06-07
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
- CVE-2021-31252MEDIUMCVSS 6.1EG 6.12021-06-04
An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to c…
- CVE-2021-25640MEDIUMCVSS 6.1EG 6.12021-06-01
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
- CVE-2021-32645MEDIUMCVSS 6.1EG 6.12021-05-27
Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is possible to have open redirects where users can be redirected from your site to any other site using a specially crafte…
- CVE-2020-36365MEDIUMCVSS 6.1EG 6.12021-05-19
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
- CVE-2021-24288MEDIUMCVSS 6.1EG 6.12021-05-17
When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.
- CVE-2021-27612MEDIUMCVSS 6.1EG 6.12021-05-11
In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.
- CVE-2020-13662MEDIUMCVSS 6.1EG 6.12021-05-05
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.
- CVE-2020-23015MEDIUMCVSS 6.1EG 6.12021-05-03
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
- CVE-2021-29137MEDIUMCVSS 6.1EG 6.12021-04-29
A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-31879MEDIUMCVSS 6.1EG 6.12021-04-29
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
- CVE-2020-21998MEDIUMCVSS 6.1EG 6.12021-04-27
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user click…
- CVE-2021-24210MEDIUMCVSS 6.1EG 6.12021-04-05
There is an open redirect in the PhastPress WordPress plugin before 1.111 that allows an attacker to malform a request to a page with the plugin and then redirect the victim to a malicious page. There is also a support comment from another…
- CVE-2021-24165MEDIUMCVSS 6.1EG 6.12021-04-05
In the Ninja Forms Contact Form WordPress plugin before 3.4.34, the wp_ajax_nf_oauth_connect AJAX action was vulnerable to open redirect due to the use of a user supplied redirect parameter and no protection in place.
- CVE-2020-9995MEDIUMCVSS 6.1EG 6.12021-04-02
An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Server 5.11. Processing a maliciously crafted URL may lead to an open redirect or cross site scripting.
- CVE-2021-29652MEDIUMCVSS 6.1EG 6.12021-04-02
Pomerium from version 0.10.0-0.13.3 has an Open Redirect in the user sign-in/out process
- CVE-2021-29651MEDIUMCVSS 6.1EG 6.12021-04-02
Pomerium before 0.13.4 has an Open Redirect (issue 1 of 2).
- CVE-2020-24550MEDIUMCVSS 6.1EG 6.12021-03-31
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.
- CVE-2021-1629MEDIUMCVSS 6.1EG 6.12021-03-26
Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
- CVE-2019-14831MEDIUMCVSS 6.1EG 6.12021-03-19
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode wa…
- CVE-2019-14830MEDIUMCVSS 6.1EG 6.12021-03-19
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access …
- CVE-2021-21491MEDIUMCVSS 6.1EG 6.12021-03-10
SAP Netweaver Application Server Java (Applications based on WebDynpro Java) versions 7.00, 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
- CVE-2020-28150MEDIUMCVSS 6.1EG 6.12021-03-09
I-Net Software Clear Reports 20.10.136 web application accepts a user-controlled input that specifies a link to an external site, and uses the user supplied data in a Redirect.
- CVE-2021-3189MEDIUMCVSS 6.1EG 6.12021-02-19
The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.
- CVE-2021-27404MEDIUMCVSS 6.1EG 6.12021-02-19
Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header.
- CVE-2020-35560MEDIUMCVSS 6.1EG 6.12021-02-16
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.
- CVE-2021-22984MEDIUMCVSS 6.1EG 6.12021-02-12
On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with…
- CVE-2020-13565MEDIUMCVSS 6.1EG 6.12021-02-10
An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request ca…
- CVE-2021-21478MEDIUMCVSS 6.1EG 6.12021-02-09
SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
- CVE-2021-21476MEDIUMCVSS 6.1EG 6.12021-02-09
SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
- CVE-2020-22840MEDIUMCVSS 6.1EG 6.12021-02-09
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
- CVE-2021-25757MEDIUMCVSS 6.1EG 6.12021-02-03
In JetBrains Hub before 2020.1.12629, an open redirect was possible.
- CVE-2020-1723MEDIUMCVSS 6.1EG 6.12021-01-28
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
- CVE-2020-26979MEDIUMCVSS 6.1EG 6.12021-01-07
When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a …
- CVE-2020-29498MEDIUMCVSS 6.1EG 6.12021-01-04
Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the vic…
- CVE-2020-35678MEDIUMCVSS 6.1EG 6.12020-12-27
Autobahn|Python before 20.12.3 allows redirect header injection.
- CVE-2020-27729MEDIUMCVSS 6.1EG 6.12020-12-24
In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a malicious user to build an open redirect URI.
- CVE-2020-4840MEDIUMCVSS 6.1EG 6.12020-12-21
IBM Security Secret Server 10.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to s…
- CVE-2020-26275MEDIUMCVSS 6.1EG 6.12020-12-21
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open redirect vulnerability co…
- CVE-2020-25901MEDIUMCVSS 6.1EG 6.12020-12-18
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.
- CVE-2020-27340MEDIUMCVSS 6.1EG 6.12020-12-18
The online help portal of Mitel MiCollab before 9.2 could allow an attacker to redirect a user to an unauthorized website by executing malicious script due to insufficient access control.
- CVE-2020-4849MEDIUMCVSS 6.1EG 6.12020-12-15
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a ph…
- CVE-2020-26836MEDIUMCVSS 6.1EG 6.12020-12-09
SAP Solution Manager (Trace Analysis), version - 720, allows for misuse of a parameter in the application URL leading to Open Redirect vulnerability, an attacker can enter a link to malicious site which could trick the user to enter creden…
- CVE-2020-29565MEDIUMCVSS 6.1EG 6.12020-12-04
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in …
- CVE-2020-27816MEDIUMCVSS 6.1EG 6.12020-12-02
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on t…
- CVE-2020-28726MEDIUMCVSS 6.1EG 6.12020-11-24
Open redirect in SeedDMS 6.0.13 via the dropfolderfileform1 parameter to out/out.AddDocument.php.
- CVE-2020-15300MEDIUMCVSS 6.1EG 6.12020-11-18
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
- CVE-2020-28724MEDIUMCVSS 6.1EG 6.12020-11-18
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
- CVE-2020-26161MEDIUMCVSS 6.1EG 6.12020-10-26
In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.
- CVE-2020-6365MEDIUMCVSS 6.1EG 6.12020-10-15
SAP NetWeaver AS Java, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, Start Page allows an unauthenticated remote attacker to redirect users to a malicious site due to insufficient reverse tabnabbing URL validation. The attacker coul…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →