CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,776 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 27 of 36
- CVE-2024-0854MEDIUMCVSS 5.4EG 5.42024-01-24
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote authenticated users to cond…
- CVE-2024-0319MEDIUMCVSS 5.4EG 5.42024-01-15
Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious page by changing the 'redirect_uri' parameter.
- CVE-2024-21734MEDIUMCVSS 5.4EG 5.42024-01-09
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the applica…
- CVE-2023-51517MEDIUMCVSS 5.4EG 5.42023-12-29
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.
- CVE-2023-51675MEDIUMCVSS 5.4EG 5.42023-12-29
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & R…
- CVE-2023-42502MEDIUMCVSS 5.4EG 5.42023-11-28
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site by spoofing the HTTP Host header, users could be redirected to this site when clicking on that specific dataset. This issue affects …
- CVE-2023-5610MEDIUMCVSS 5.4EG 5.42023-11-20
The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect
- CVE-2023-5445MEDIUMCVSS 5.4EG 5.42023-11-17
An open redirect vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2, allows a remote low privileged user to modify the URL parameter for the purpose of redirecting URL request(s) to a malicious site. This impacts the dashb…
- CVE-2023-23957MEDIUMCVSS 5.4EG 5.42023-09-19
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
- CVE-2023-35948MEDIUMCVSS 5.4EG 5.42023-07-06
Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redirect vulnerability in the "Sign In with GitHub" functionality of Novu's open-source repository. It could have allowed an…
- CVE-2023-29307MEDIUMCVSS 5.4EG 5.42023-06-15
Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to mali…
- CVE-2022-4946MEDIUMCVSS 5.4EG 5.42023-06-05
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will red…
- CVE-2023-0155MEDIUMCVSS 5.4EG 5.42023-05-03
An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown
- CVE-2023-2000MEDIUMCVSS 5.4EG 5.42023-05-02
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
- CVE-2023-22729MEDIUMCVSS 5.4EG 5.42023-04-26
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legit…
- CVE-2023-28628MEDIUMCVSS 5.4EG 5.42023-03-27
lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious URLs to be parsed by the `lambdaisland/uri` and return the wrong authority. This issue is si…
- CVE-2023-22266MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22265MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22264MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22263MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22262MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22261MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22260MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22259MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22258MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22257MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22256MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-27292MEDIUMCVSS 5.4EG 5.42023-02-28
An open redirect vulnerability exposes OpenCATS to template injection due to improper validation of user-supplied GET parameters.
- CVE-2023-0552MEDIUMCVSS 5.4EG 5.42023-02-27
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
- CVE-2022-43721MEDIUMCVSS 5.4EG 5.42023-01-16
An authenticated attacker with update datasets permission could change a dataset link to an untrusted site, users could be redirected to this site when clicking on that specific dataset. This issue affects Apache Superset version 1.5.2 an…
- CVE-2022-41208MEDIUMCVSS 5.4EG 5.42022-11-08
Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with user privileges to alter current user session. On successful exploitation, the attacker can view or modify information,…
- CVE-2022-40257MEDIUMCVSS 5.4EG 5.42022-10-10
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via a crafted email with HTML content in the Subject field.
- CVE-2022-40248MEDIUMCVSS 5.4EG 5.42022-10-10
An HTML injection vulnerability exists in CERT/CC VINCE software prior to 1.50.4. An authenticated attacker can inject arbitrary HTML via form using the "Product Affected" field.
- CVE-2022-25295MEDIUMCVSS 5.4EG 5.42022-09-11
This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a re…
- CVE-2022-27110MEDIUMCVSS 5.4EG 5.42022-04-06
OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
- CVE-2022-27109MEDIUMCVSS 5.4EG 5.42022-04-06
OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
- CVE-2022-27090MEDIUMCVSS 5.4EG 5.42022-03-21
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.
- CVE-2021-23495MEDIUMCVSS 5.4EG 5.42022-02-25
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
- CVE-2022-25196MEDIUMCVSS 5.4EG 5.42022-02-15
Jenkins GitLab Authentication Plugin 1.13 and earlier records the HTTP Referer header as part of the URL query parameters when the authentication process starts, allowing attackers with access to Jenkins to craft a URL that will redirect u…
- CVE-2021-42564MEDIUMCVSS 5.4EG 5.42021-11-30
An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta ht…
- CVE-2021-36332MEDIUMCVSS 5.4EG 5.42021-11-23
Dell EMC CloudLink 7.1 and all prior versions contain a HTML and Javascript Injection Vulnerability. A remote low privileged attacker, may potentially exploit this vulnerability, directing end user to arbitrary and potentially malicious we…
- CVE-2021-1500MEDIUMCVSS 5.4EG 5.42021-11-04
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the URL p…
- CVE-2021-3851MEDIUMCVSS 5.4EG 5.42021-10-19
firefly-iii is vulnerable to URL Redirection to Untrusted Site
- CVE-2021-35205MEDIUMCVSS 5.4EG 5.42021-09-30
NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.
- CVE-2021-23401MEDIUMCVSS 5.4EG 5.42021-07-05
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evi…
- CVE-2020-23182MEDIUMCVSS 5.4EG 5.42021-07-02
The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.
- CVE-2021-23393MEDIUMCVSS 5.4EG 5.42021-06-11
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.c…
- CVE-2021-23387MEDIUMCVSS 5.4EG 5.42021-05-24
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in in…
- CVE-2021-23384MEDIUMCVSS 5.4EG 5.42021-05-17
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable …
- CVE-2021-27352MEDIUMCVSS 5.4EG 5.42021-03-29
An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →