CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 21 of 36
- CVE-2019-15772MEDIUMCVSS 6.1EG 6.12019-08-29
The nd-donations plugin before 1.4 for WordPress has a nopriv_ AJAX action that allows modification of the siteurl setting.
- CVE-2016-6154MEDIUMCVSS 6.1EG 6.12019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
- CVE-2019-13422MEDIUMCVSS 6.1EG 6.12019-08-23
Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an attacker can redirect the user to a potentially malicious site upon Kibana login.
- CVE-2019-11589MEDIUMCVSS 6.1EG 6.12019-08-23
The ChangeSharedFilterOwner resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to attack users, in some cases be able to obtain a user's Cros…
- CVE-2019-11585MEDIUMCVSS 6.1EG 6.12019-08-23
The startup.jsp resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to redirect users to a different website which they may use as part of per…
- CVE-2019-1954MEDIUMCVSS 6.1EG 6.12019-08-08
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. The vulnerability is due to improper input validatio…
- CVE-2019-10372MEDIUMCVSS 6.1EG 6.12019-08-07
An open redirect vulnerability in Jenkins Gitlab Authentication Plugin 1.4 and earlier in GitLabSecurityRealm.java allows attackers to redirect users to a URL outside Jenkins after successful login.
- CVE-2016-10769MEDIUMCVSS 6.1EG 6.12019-08-05
cPanel before 60.0.25 allows an open redirect via /cgi-sys/FormMail-clone.cgi (SEC-162).
- CVE-2018-20929MEDIUMCVSS 6.1EG 6.12019-08-01
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
- CVE-2018-20867MEDIUMCVSS 6.1EG 6.12019-07-30
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
- CVE-2019-1020016MEDIUMCVSS 6.1EG 6.12019-07-29
ASH-AIO before 2.0.0.3 allows an open redirect.
- CVE-2019-1010290MEDIUMCVSS 6.1EG 6.12019-07-16
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must op…
- CVE-2019-1075MEDIUMCVSS 6.1EG 6.12019-07-15
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
- CVE-2018-12621MEDIUMCVSS 6.1EG 6.12019-07-05
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
- CVE-2019-5969MEDIUMCVSS 6.1EG 6.12019-07-05
Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites and conduct phishing attacks via the process of login.
- CVE-2019-5965MEDIUMCVSS 6.1EG 6.12019-07-05
Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2019-10721MEDIUMCVSS 6.1EG 6.12019-07-03
BlogEngine.NET 3.3.7.0 allows a Client Side URL Redirect via the ReturnUrl parameter, related to BlogEngine/BlogEngine.Core/Services/Security/Security.cs, login.aspx, and register.aspx.
- CVE-2019-13175MEDIUMCVSS 6.1EG 6.12019-07-02
Read the Docs before 3.5.1 has an Open Redirect if certain user-defined redirects are used. This affects private instances of Read the Docs (in addition to the public readthedocs.org web sites).
- CVE-2019-7275MEDIUMCVSS 6.1EG 6.12019-07-01
Optergy Proton/Enterprise devices allow Open Redirect.
- CVE-2019-13038MEDIUMCVSS 6.1EG 6.12019-06-29
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
- CVE-2017-14394MEDIUMCVSS 6.1EG 6.12019-06-19
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via …
- CVE-2019-3477MEDIUMCVSS 6.1EG 6.12019-06-07
Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect.
- CVE-2019-4201MEDIUMCVSS 6.1EG 6.12019-06-06
IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exp…
- CVE-2018-13384MEDIUMCVSS 6.1EG 6.12019-06-04
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web dom…
- CVE-2019-5946MEDIUMCVSS 6.1EG 6.12019-05-17
Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the Login Screen.
- CVE-2019-10117MEDIUMCVSS 6.1EG 6.12019-05-16
An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for…
- CVE-2019-8951MEDIUMCVSS 6.1EG 6.12019-05-13
An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote attacker to redirect users to an arbitrary URL. Affected hardware products: Bosch D…
- CVE-2018-12300MEDIUMCVSS 6.1EG 6.12019-05-13
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
- CVE-2018-14931MEDIUMCVSS 6.1EG 6.12019-04-30
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.
- CVE-2019-4166MEDIUMCVSS 6.1EG 6.12019-04-30
IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL di…
- CVE-2019-10955MEDIUMCVSS 6.1EG 6.12019-04-25
In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers…
- CVE-2019-4092MEDIUMCVSS 6.1EG 6.12019-04-25
IBM Content Navigator 2.0.3 and 3.0CD could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerabilit…
- CVE-2019-8995MEDIUMCVSS 6.1EG 6.12019-04-24
The workspace client, openspace client, and app development client of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribution for TIBCO Silver Fabric, and TIBCO Silver Fabric Enabler for ActiveMatrix BPM contain a…
- CVE-2018-20698MEDIUMCVSS 6.1EG 6.12019-04-09
The floragunn Search Guard plugin before 6.x-16 for Kibana allows URL injection for login redirects on the login page when basePath is set.
- CVE-2019-11016MEDIUMCVSS 6.1EG 6.12019-04-08
Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect.
- CVE-2019-10856MEDIUMCVSS 6.1EG 6.12019-04-04
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.
- CVE-2018-15180MEDIUMCVSS 6.1EG 6.12019-04-02
qTest Portal in QASymphony qTest Manager 9.0.0 has an Open Redirect via the /portal/loginform redirect parameter.
- CVE-2017-18109MEDIUMCVSS 6.1EG 6.12019-03-29
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack v…
- CVE-2019-10255MEDIUMCVSS 6.1EG 6.12019-03-28
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successfu…
- CVE-2019-9915MEDIUMCVSS 6.1EG 6.12019-03-22
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
- CVE-2019-9837MEDIUMCVSS 6.1EG 6.12019-03-21
Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redirect_uri field in an OAuth authorization request (that results in an error response) with the 'openid…
- CVE-2019-7416MEDIUMCVSS 6.1EG 6.12019-03-21
XSS and/or a Client Side URL Redirect exists in OpenText Documentum Webtop 5.3 SP2. The parameter startat in "/webtop/help/en/default.htm" is vulnerable.
- CVE-2018-17422MEDIUMCVSS 6.1EG 6.12019-03-07
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
- CVE-2018-19106MEDIUMCVSS 6.1EG 6.12019-02-20
Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959.
- CVE-2016-10742MEDIUMCVSS 6.1EG 6.12019-02-17
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
- CVE-2019-5915MEDIUMCVSS 6.1EG 6.12019-02-13
Open redirect vulnerability in OpenAM (Open Source Edition) 13.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted page.
- CVE-2019-3912MEDIUMCVSS 6.1EG 6.12019-01-30
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.
- CVE-2019-6780MEDIUMCVSS 6.1EG 6.12019-01-24
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPostFilter.php omits noopener and noreferrer.
- CVE-2018-16191MEDIUMCVSS 6.1EG 6.12019-01-09
Open redirect vulnerability in EC-CUBE (EC-CUBE 3.0.0, EC-CUBE 3.0.1, EC-CUBE 3.0.2, EC-CUBE 3.0.3, EC-CUBE 3.0.4, EC-CUBE 3.0.5, EC-CUBE 3.0.6, EC-CUBE 3.0.7, EC-CUBE 3.0.8, EC-CUBE 3.0.9, EC-CUBE 3.0.10, EC-CUBE 3.0.11, EC-CUBE 3.0.12, E…
- CVE-2018-16174MEDIUMCVSS 6.1EG 6.12019-01-09
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →