CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 20 of 36
- CVE-2019-6696MEDIUMCVSS 6.1EG 6.12020-03-15
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password chan…
- CVE-2019-4595MEDIUMCVSS 6.1EG 6.12020-02-24
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker …
- CVE-2019-20479MEDIUMCVSS 6.1EG 6.12020-02-20
A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
- CVE-2014-9617MEDIUMCVSS 6.1EG 6.12020-02-19
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
- CVE-2019-19758MEDIUMCVSS 6.1EG 6.12020-02-14
A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page.
- CVE-2013-2621MEDIUMCVSS 6.1EG 6.12020-02-03
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
- CVE-2013-2764MEDIUMCVSS 6.1EG 6.12020-01-28
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
- CVE-2019-4631MEDIUMCVSS 6.1EG 6.12020-01-28
IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to s…
- CVE-2020-7936MEDIUMCVSS 6.1EG 6.12020-01-23
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
- CVE-2015-9540MEDIUMCVSS 6.1EG 6.12020-01-04
Chamilo LMS through 1.9.10.2 allows a link_goto.php?link_url= open redirect, a related issue to CVE-2015-5503.
- CVE-2019-20225MEDIUMCVSS 6.1EG 6.12020-01-02
MyBB before 1.8.22 allows an open redirect on login.
- CVE-2019-6035MEDIUMCVSS 6.1EG 6.12019-12-26
Open redirect vulnerability in Athenz v1.8.24 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted page.
- CVE-2019-6025MEDIUMCVSS 6.1EG 6.12019-12-26
Open redirect vulnerability in Movable Type series Movable Type 7 r.4602 (7.1.3) and earlier (Movable Type 7), Movable Type 6.5.0 and 6.5.1 (Movable Type 6.5), Movable Type 6.3.9 and earlier (Movable Type 6.3.x, 6.2.x, 6.1.x, 6.0.x), Movab…
- CVE-2019-6021MEDIUMCVSS 6.1EG 6.12019-12-26
Open redirect vulnerability in Library Information Management System LIMEDIO all versions allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
- CVE-2019-6020MEDIUMCVSS 6.1EG 6.12019-12-26
Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi…
- CVE-2018-18288MEDIUMCVSS 6.1EG 6.12019-12-26
CrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.
- CVE-2019-18781MEDIUMCVSS 6.1EG 6.12019-12-18
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
- CVE-2019-8791MEDIUMCVSS 6.1EG 6.12019-12-18
An issue existed in the parsing of URL schemes. This issue was addressed with improved URL validation. This issue is fixed in Shazam Android App Version 9.25.0, Shazam iOS App Version 12.11.0. Processing a maliciously crafted URL may lead …
- CVE-2019-19775MEDIUMCVSS 6.1EG 6.12019-12-18
The image thumbnailing handler in Zulip Server versions 1.9.0 to before 2.0.8 allowed an open redirect that was visible to logged-in users.
- CVE-2014-3652MEDIUMCVSS 6.1EG 6.12019-12-15
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
- CVE-2019-19709MEDIUMCVSS 6.1EG 6.12019-12-11
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when e…
- CVE-2019-1486MEDIUMCVSS 6.1EG 6.12019-12-10
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.
- CVE-2019-19703MEDIUMCVSS 6.1EG 6.12019-12-10
In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
- CVE-2016-1000107MEDIUMCVSS 6.1EG 6.12019-12-10
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to …
- CVE-2016-1000108MEDIUMCVSS 6.1EG 6.12019-12-10
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow …
- CVE-2016-1000110MEDIUMCVSS 6.1EG 6.12019-11-27
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
- CVE-2019-18451MEDIUMCVSS 6.1EG 6.12019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.
- CVE-2019-15688MEDIUMCVSS 6.1EG 6.12019-11-26
Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user a…
- CVE-2019-14857MEDIUMCVSS 6.1EG 6.12019-11-26
A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon.
- CVE-2014-2213MEDIUMCVSS 6.1EG 6.12019-11-22
Open redirect vulnerability in the password reset functionality in POSH 3.0 through 3.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to portal/scr_sendm…
- CVE-2019-15073MEDIUMCVSS 6.1EG 6.12019-11-20
An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies a…
- CVE-2018-13257MEDIUMCVSS 6.1EG 6.12019-11-18
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS se…
- CVE-2019-18815MEDIUMCVSS 6.1EG 6.12019-11-07
PopojiCMS 2.0.1 allows refer= Open Redirection.
- CVE-2010-2471MEDIUMCVSS 6.1EG 6.12019-11-06
Drupal versions 5.x and 6.x has open redirection
- CVE-2010-3661MEDIUMCVSS 6.1EG 6.12019-11-01
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
- CVE-2019-15041MEDIUMCVSS 6.1EG 6.12019-10-01
JetBrains YouTrack versions before 2019.1.52545 allowed unbounded URL whitelisting because of Inclusion of Functionality from an Untrusted Control Sphere.
- CVE-2019-14912MEDIUMCVSS 6.1EG 6.12019-09-20
An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.
- CVE-2019-16393MEDIUMCVSS 6.1EG 6.12019-09-17
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
- CVE-2019-6009MEDIUMCVSS 6.1EG 6.12019-09-12
Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2019-6004MEDIUMCVSS 6.1EG 6.12019-09-12
Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver.2.1.2.4 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via u…
- CVE-2019-5978MEDIUMCVSS 6.1EG 6.12019-09-12
Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the application 'Scheduler'.
- CVE-2019-16220MEDIUMCVSS 6.1EG 6.12019-09-11
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
- CVE-2019-14223MEDIUMCVSS 6.1EG 6.12019-09-06
An issue was discovered in Alfresco Community Edition versions below 5.2.6, 6.0.N and 6.1.N. The Alfresco Share application is vulnerable to an Open Redirect attack via a crafted POST request. By manipulating the POST parameters, an attack…
- CVE-2019-15820MEDIUMCVSS 6.1EG 6.12019-08-30
The login-or-logout-menu-item plugin before 1.2.0 for WordPress has no requirement for lolmi_save_settings authentication.
- CVE-2019-15818MEDIUMCVSS 6.1EG 6.12019-08-30
The simple-301-redirects-addon-bulk-uploader plugin through 1.2.4 for WordPress has no requirement for authentication for action=bulk301export or action=bulk301clearlist.
- CVE-2019-15771MEDIUMCVSS 6.1EG 6.12019-08-29
The nd-shortcodes plugin before 6.0 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-15776MEDIUMCVSS 6.1EG 6.12019-08-29
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
- CVE-2019-15775MEDIUMCVSS 6.1EG 6.12019-08-29
The nd-learning plugin before 4.8 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-15774MEDIUMCVSS 6.1EG 6.12019-08-29
The nd-booking plugin before 2.5 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2019-15773MEDIUMCVSS 6.1EG 6.12019-08-29
The nd-travel plugin before 1.7 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →