CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 23 of 36
- CVE-2018-1220MEDIUMCVSS 6.1EG 6.12018-03-08
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the intent of obtainin…
- CVE-2018-7473MEDIUMCVSS 6.1EG 6.12018-03-07
Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL.
- CVE-2015-3898MEDIUMCVSS 6.1EG 6.12018-02-28
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp o…
- CVE-2018-6324MEDIUMCVSS 6.1EG 6.12018-02-16
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
- CVE-2017-8945MEDIUMCVSS 6.1EG 6.12018-02-15
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.
- CVE-2017-18178MEDIUMCVSS 6.1EG 6.12018-02-12
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
- CVE-2018-6520MEDIUMCVSS 6.1EG 6.12018-02-02
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
- CVE-2017-2166MEDIUMCVSS 6.1EG 6.12018-01-26
Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2018-6200MEDIUMCVSS 6.1EG 6.12018-01-25
vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.
- CVE-2018-0097MEDIUMCVSS 6.1EG 6.12018-01-18
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of t…
- CVE-2017-1534MEDIUMCVSS 6.1EG 6.12018-01-10
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit t…
- CVE-2017-1668MEDIUMCVSS 6.1EG 6.12018-01-09
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this…
- CVE-2017-1000484MEDIUMCVSS 6.1EG 6.12018-01-03
By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination wi…
- CVE-2017-1000481MEDIUMCVSS 6.1EG 6.12018-01-03
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might t…
- CVE-2017-1000434MEDIUMCVSS 6.1EG 6.12018-01-02
Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attacker controlled page classes/Furigana.php: header('location:'.urldecode($_GET['furikake-red…
- CVE-2017-1558MEDIUMCVSS 6.1EG 6.12017-12-13
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerabil…
- CVE-2017-16679MEDIUMCVSS 6.1EG 6.12017-12-12
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.52, that allows an attacker…
- CVE-2017-11482MEDIUMCVSS 6.1EG 6.12017-12-08
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects t…
- CVE-2017-3105MEDIUMCVSS 6.1EG 6.12017-12-01
Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.
- CVE-2017-12344MEDIUMCVSS 6.1EG 6.12017-11-30
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content int…
- CVE-2017-1000163MEDIUMCVSS 6.1EG 6.12017-11-17
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.
- CVE-2017-16761MEDIUMCVSS 6.1EG 6.12017-11-10
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
- CVE-2017-14358MEDIUMCVSS 6.1EG 6.12017-10-31
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untr…
- CVE-2015-6961MEDIUMCVSS 6.1EG 6.12017-10-18
Open redirect vulnerability in gluon/tools.py in Web2py 2.9.11 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the _next parameter to user/logout.
- CVE-2015-7943MEDIUMCVSS 6.1EG 6.12017-10-18
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web…
- CVE-2017-8047MEDIUMCVSS 6.1EG 6.12017-10-04
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. A…
- CVE-2017-14525MEDIUMCVSS 6.1EG 6.12017-09-28
Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.h…
- CVE-2017-14524MEDIUMCVSS 6.1EG 6.12017-09-28
Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/de…
- CVE-2015-4668MEDIUMCVSS 6.1EG 6.12017-09-25
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
- CVE-2015-5608MEDIUMCVSS 6.1EG 6.12017-09-20
Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.
- CVE-2015-3880MEDIUMCVSS 6.1EG 6.12017-09-19
Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2017-1002150MEDIUMCVSS 6.1EG 6.12017-09-14
python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection
- CVE-2015-2750MEDIUMCVSS 6.1EG 6.12017-09-13
Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial seq…
- CVE-2015-2749MEDIUMCVSS 6.1EG 6.12017-09-13
Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
- CVE-2015-5054MEDIUMCVSS 6.1EG 6.12017-09-11
Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
- CVE-2017-1450MEDIUMCVSS 6.1EG 6.12017-08-31
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability t…
- CVE-2017-14038MEDIUMCVSS 6.1EG 6.12017-08-30
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
- CVE-2017-1195MEDIUMCVSS 6.1EG 6.12017-08-29
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could expl…
- CVE-2017-1489MEDIUMCVSS 6.1EG 6.12017-08-29
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128…
- CVE-2017-12138MEDIUMCVSS 6.1EG 6.12017-08-02
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
- CVE-2017-11718MEDIUMCVSS 6.1EG 6.12017-07-28
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
- CVE-2017-11586MEDIUMCVSS 6.1EG 6.12017-07-24
dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.
- CVE-2017-1223MEDIUMCVSS 6.1EG 6.12017-07-19
IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof…
- CVE-2017-1000070MEDIUMCVSS 6.1EG 6.12017-07-17
The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819
- CVE-2017-1000027MEDIUMCVSS 6.1EG 6.12017-07-17
Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.
- CVE-2017-1000013MEDIUMCVSS 6.1EG 6.12017-07-17
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness
- CVE-2016-8947MEDIUMCVSS 6.1EG 6.12017-07-12
IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera…
- CVE-2017-8621MEDIUMCVSS 6.1EG 6.12017-07-11
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".
- CVE-2017-1398MEDIUMCVSS 6.1EG 6.12017-07-10
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web sit…
- CVE-2017-2217MEDIUMCVSS 6.1EG 6.12017-07-07
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →