CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 22 of 36
- CVE-2018-0688MEDIUMCVSS 6.1EG 6.12019-01-09
Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 Septem…
- CVE-2018-19790MEDIUMCVSS 6.1EG 6.12018-12-18
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms,…
- CVE-2018-7804MEDIUMCVSS 6.1EG 6.12018-12-17
A URL Redirection to Untrusted Site vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a user clicking on a specially crafted link can be redirected to a URL of the attacker's c…
- CVE-2018-7797MEDIUMCVSS 6.1EG 6.12018-12-17
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure …
- CVE-2018-19796MEDIUMCVSS 6.1EG 6.12018-12-03
An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
- CVE-2018-11067MEDIUMCVSS 6.1EG 6.12018-11-26
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection v…
- CVE-2018-17948MEDIUMCVSS 6.1EG 6.12018-11-20
An open redirect vulnerability exists in the Access Manager Identity Provider prior to 4.4 SP3.
- CVE-2018-2476MEDIUMCVSS 6.1EG 6.12018-11-13
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
- CVE-2018-14658MEDIUMCVSS 6.1EG 6.12018-11-13
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
- CVE-2018-13402MEDIUMCVSS 6.1EG 6.12018-10-23
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.…
- CVE-2018-13401MEDIUMCVSS 6.1EG 6.12018-10-23
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from…
- CVE-2018-12675MEDIUMCVSS 6.1EG 6.12018-10-19
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpect…
- CVE-2018-15493MEDIUMCVSS 6.1EG 6.12018-10-17
vBulletin 5.4.3 has an Open Redirect.
- CVE-2018-17870MEDIUMCVSS 6.1EG 6.12018-10-01
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683.
- CVE-2018-16954MEDIUMCVSS 6.1EG 6.12018-09-18
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parameter is not validated by the application …
- CVE-2018-17074MEDIUMCVSS 6.1EG 6.12018-09-16
The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.
- CVE-2018-5548MEDIUMCVSS 6.1EG 6.12018-09-13
On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect URI value using diffe…
- CVE-2018-16761MEDIUMCVSS 6.1EG 6.12018-09-09
Eventum before 3.4.0 has an open redirect vulnerability.
- CVE-2018-14398MEDIUMCVSS 6.1EG 6.12018-09-07
An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.
- CVE-2018-14366MEDIUMCVSS 6.1EG 6.12018-09-06
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
- CVE-2018-1000671MEDIUMCVSS 6.1EG 6.12018-09-06
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via dat…
- CVE-2018-15683MEDIUMCVSS 6.1EG 6.12018-09-05
An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be instantly redirected.
- CVE-2018-7692MEDIUMCVSS 6.1EG 6.12018-08-09
Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.
- CVE-2018-15178MEDIUMCVSS 6.1EG 6.12018-08-08
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isVal…
- CVE-2018-7091MEDIUMCVSS 6.1EG 6.12018-08-06
HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.
- CVE-2018-14574MEDIUMCVSS 6.1EG 6.12018-08-03
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
- CVE-2018-14474MEDIUMCVSS 6.1EG 6.12018-07-20
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
- CVE-2018-14381MEDIUMCVSS 6.1EG 6.12018-07-18
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
- CVE-2013-0594MEDIUMCVSS 6.1EG 6.12018-07-11
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.
- CVE-2018-1355MEDIUMCVSS 6.1EG 6.12018-06-27
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiVi…
- CVE-2018-11041MEDIUMCVSS 6.1EG 6.12018-06-25
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for in…
- CVE-2018-11408MEDIUMCVSS 6.1EG 6.12018-06-13
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlin…
- CVE-2017-16652MEDIUMCVSS 6.1EG 6.12018-06-13
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path par…
- CVE-2017-5389MEDIUMCVSS 6.1EG 6.12018-06-11
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then i…
- CVE-2017-16224MEDIUMCVSS 6.1EG 6.12018-06-07
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to…
- CVE-2018-3743MEDIUMCVSS 6.1EG 6.12018-06-01
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
- CVE-2018-10651MEDIUMCVSS 6.1EG 6.12018-05-23
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- CVE-2015-8094MEDIUMCVSS 6.1EG 6.12018-05-22
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
- CVE-2018-11119MEDIUMCVSS 6.1EG 6.12018-05-17
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
- CVE-2018-10678MEDIUMCVSS 6.1EG 6.12018-05-13
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
- CVE-2018-1000174MEDIUMCVSS 6.1EG 6.12018-05-08
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
- CVE-2018-1248MEDIUMCVSS 6.1EG 6.12018-05-08
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and…
- CVE-2017-18262MEDIUMCVSS 6.1EG 6.12018-04-30
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/s…
- CVE-2018-10101MEDIUMCVSS 6.1EG 6.12018-04-16
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
- CVE-2018-10100MEDIUMCVSS 6.1EG 6.12018-04-16
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
- CVE-2017-0364MEDIUMCVSS 6.1EG 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
- CVE-2017-0363MEDIUMCVSS 6.1EG 6.12018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
- CVE-2017-7153MEDIUMCVSS 6.1EG 6.12018-04-03
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS …
- CVE-2018-3819MEDIUMCVSS 6.1EG 6.12018-03-30
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an…
- CVE-2018-8937MEDIUMCVSS 6.1EG 6.12018-03-26
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScrip…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →