CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 19 of 36
- CVE-2020-24551MEDIUMCVSS 6.1EG 6.12020-10-14
IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login credentials.
- CVE-2020-15234MEDIUMCVSS 6.1EG 6.12020-10-02
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL provided at the OAuth2 Authorization Endpoint where compared usi…
- CVE-2020-15233MEDIUMCVSS 6.1EG 6.12020-10-02
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before version 0.34.1, there is an issue in which an an attacker can override the registered redirect URL by performing an OAuth flo…
- CVE-2020-15677MEDIUMCVSS 6.1EG 6.12020-10-01
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was…
- CVE-2019-15974MEDIUMCVSS 6.1EG 6.12020-09-23
A vulnerability in the web interface of Cisco Managed Services Accelerator (MSX) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the param…
- CVE-2020-5627MEDIUMCVSS 6.1EG 6.12020-09-09
Yodobashi App for Android versions 1.8.7 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
- CVE-2020-5623MEDIUMCVSS 6.1EG 6.12020-08-28
NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a…
- CVE-2020-24598MEDIUMCVSS 6.1EG 6.12020-08-26
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
- CVE-2020-5541MEDIUMCVSS 6.1EG 6.12020-08-25
Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.
- CVE-2020-4598MEDIUMCVSS 6.1EG 6.12020-08-24
IBM Security Guardium Insights 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability…
- CVE-2020-4653MEDIUMCVSS 6.1EG 6.12020-08-19
IBM Planning Analytics 2.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof …
- CVE-2020-15129MEDIUMCVSS 6.1EG 6.12020-07-30
In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of …
- CVE-2019-12783MEDIUMCVSS 6.1EG 6.12020-07-14
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "…
- CVE-2019-20901MEDIUMCVSS 6.1EG 6.12020-07-13
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redire…
- CVE-2020-5607MEDIUMCVSS 6.1EG 6.12020-07-10
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2020-11882MEDIUMCVSS 6.1EG 6.12020-07-07
The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can be delivered either via links or by directly calling the act…
- CVE-2017-18897MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
- CVE-2017-18891MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
- CVE-2020-14454MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
- CVE-2020-14446MEDIUMCVSS 6.1EG 6.12020-06-18
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
- CVE-2020-3337MEDIUMCVSS 6.1EG 6.12020-06-18
A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validation of the URL parameters in an HTTP request…
- CVE-2020-1323MEDIUMCVSS 6.1EG 6.12020-06-09
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint…
- CVE-2020-1220MEDIUMCVSS 6.1EG 6.12020-06-09
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
- CVE-2020-10959MEDIUMCVSS 6.1EG 6.12020-06-02
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
- CVE-2020-13486MEDIUMCVSS 6.1EG 6.12020-05-25
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
- CVE-2020-13121MEDIUMCVSS 6.1EG 6.12020-05-16
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
- CVE-2020-5409MEDIUMCVSS 6.1EG 6.12020-05-14
Pivotal Concourse, most versions prior to 6.0.0, allows redirects to untrusted websites in its login flow. A remote unauthenticated attacker could convince a user to click on a link using the OAuth redirect link with an untrusted website a…
- CVE-2020-12699MEDIUMCVSS 6.1EG 6.12020-05-13
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
- CVE-2020-3311MEDIUMCVSS 6.1EG 6.12020-05-06
A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of H…
- CVE-2020-3178MEDIUMCVSS 6.1EG 6.12020-05-06
Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities a…
- CVE-2020-12666MEDIUMCVSS 6.1EG 6.12020-05-05
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
- CVE-2020-11034MEDIUMCVSS 6.1EG 6.12020-05-05
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
- CVE-2019-4209MEDIUMCVSS 6.1EG 6.12020-05-01
HCL Connections v5.5, v6.0, and v6.5 contains an open redirect vulnerability which could be exploited by an attacker to conduct phishing attacks.
- CVE-2020-12283MEDIUMCVSS 6.1EG 6.12020-04-30
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
- CVE-2020-5733MEDIUMCVSS 6.1EG 6.12020-04-17
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of potentially sensitive information.
- CVE-2020-5732MEDIUMCVSS 6.1EG 6.12020-04-17
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restr…
- CVE-2020-11665MEDIUMCVSS 6.1EG 6.12020-04-15
CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
- CVE-2020-11664MEDIUMCVSS 6.1EG 6.12020-04-15
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
- CVE-2020-11663MEDIUMCVSS 6.1EG 6.12020-04-15
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
- CVE-2020-3954MEDIUMCVSS 6.1EG 6.12020-04-15
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
- CVE-2020-6215MEDIUMCVSS 6.1EG 6.12020-04-14
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal creden…
- CVE-2020-6211MEDIUMCVSS 6.1EG 6.12020-04-14
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirectio…
- CVE-2020-6223MEDIUMCVSS 6.1EG 6.12020-04-14
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error…
- CVE-2020-8430MEDIUMCVSS 6.1EG 6.12020-04-13
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in the query string.
- CVE-2020-11611MEDIUMCVSS 6.1EG 6.12020-04-07
An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. Therefore any domain tha…
- CVE-2020-11515MEDIUMCVSS 6.1EG 6.12020-04-07
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this …
- CVE-2020-11529MEDIUMCVSS 6.1EG 6.12020-04-04
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
- CVE-2019-19484MEDIUMCVSS 6.1EG 6.12020-03-20
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.
- CVE-2019-14882MEDIUMCVSS 6.1EG 6.12020-03-18
A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.
- CVE-2019-6696MEDIUMCVSS 6.1EG 6.12020-03-15
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password chan…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →