CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,633 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 16 of 33
- CVE-2022-4496MEDIUMCVSS 6.1EG 6.12023-01-30
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the red…
- CVE-2022-45169MEDIUMCVSS 5.4EG 5.42024-02-21
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arb…
- CVE-2022-45402HIGHCVSS 6.1EG 8.82022-11-15
In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint.
- CVE-2022-45413MEDIUMCVSS 6.1EG 6.12022-12-22
Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not af…
- CVE-2022-45582MEDIUMCVSS 6.1EG 6.12023-08-22
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
- CVE-2022-4589MEDIUMCVSS 5.5EG 5.52022-12-17
A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected by this vulnerability is the function returnTo of the file termsandconditions/views.py. The manipulation leads to open…
- CVE-2022-45917MEDIUMCVSS 6.1EG 6.12022-12-07
ILIAS before 7.16 has an Open Redirect.
- CVE-2022-46288MEDIUMCVSS 6.1EG 6.12022-12-19
Open redirect vulnerability in DENSHI NYUSATSU CORE SYSTEM v6 R4 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted …
- CVE-2022-46407MEDIUMCVSS 4.8EG 4.82023-06-29
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of …
- CVE-2022-4644MEDIUMCVSS 6.1EG 6.12022-12-22
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.
- CVE-2022-46683MEDIUMCVSS 6.1EG 6.12022-12-12
Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is legitimately pointing to Jenkins.
- CVE-2022-46784MEDIUMCVSS 6.1EG 6.12023-02-23
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)
- CVE-2022-46886MEDIUMCVSS 5.5EG 5.52023-04-14
There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domains when clicking on a URL within a service-now domain.
- CVE-2022-4720MEDIUMCVSS 6.1EG 6.12022-12-27
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.
- CVE-2022-47500MEDIUMCVSS 6.1EG 6.12022-12-19
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component sinc…
- CVE-2022-48358HIGHCVSS 7.4EG 7.42023-03-27
The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service exceptions.
- CVE-2022-4927MEDIUMCVSS 5.5EG 6.12023-03-05
A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrus…
- CVE-2022-4946MEDIUMCVSS 5.4EG 5.42023-06-05
The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will red…
- CVE-2023-0042MEDIUMCVSS 6.1EG 6.12023-01-12
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2. GitLab Pages allows redirection to arbitrary protocols.
- CVE-2023-0155MEDIUMCVSS 5.4EG 5.42023-05-03
An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown
- CVE-2023-0552MEDIUMCVSS 5.4EG 5.42023-02-27
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
- CVE-2023-0681MEDIUMCVSS 4.3EG 6.12023-03-20
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/re…
- CVE-2023-0748MEDIUMCVSS 6.4EG 6.42023-02-08
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
- CVE-2023-0876MEDIUMCVSS 6.1EG 6.12023-03-20
The WP Meta SEO WordPress plugin before 4.5.3 does not authorize several ajax actions, allowing low-privilege users to make updates to certain data and leading to an arbitrary redirect vulnerability.
- CVE-2023-1279LOWCVSS 2.6EG 2.62023-09-01
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would re…
- CVE-2023-2000MEDIUMCVSS 5.4EG 5.42023-05-02
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
- CVE-2023-20263MEDIUMCVSS 4.7EG 4.72023-09-06
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validati…
- CVE-2023-20264MEDIUMCVSS 6.1EG 6.12023-11-01
A vulnerability in the implementation of Security Assertion Markup Language (SAML) 2.0 single sign-on (SSO) for remote access VPN in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could a…
- CVE-2023-20884MEDIUMCVSS 6.1EG 6.12023-05-30
VMware Workspace ONE Access and VMware Identity Manager contain an insecure redirect vulnerability. An unauthenticated malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading…
- CVE-2023-20886HIGHCVSS 8.8EG 8.82023-10-31
VMware Workspace ONE UEM console contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker and retrieve their SAML response to login as the victim user.
- CVE-2023-22256MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22257MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22258MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22259MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22260MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22261MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22262MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22263MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22264MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22265MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22266MEDIUMCVSS 5.4EG 5.42023-03-22
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious…
- CVE-2023-22298MEDIUMCVSS 6.1EG 6.12023-01-17
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
- CVE-2023-22418MEDIUMCVSS 6.1EG 6.12023-02-01
On versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.7, 14.1.x before 14.1.5.3, and all versions of 13.1.x, an open redirect vulnerability exists on virtual servers enabled with a BIG-IP APM access policy. This v…
- CVE-2023-22432MEDIUMCVSS 6.1EG 6.12023-03-06
Open redirect vulnerability exists in web2py versions prior to 2.23.1. When using the tool, a web2py user may be redirected to an arbitrary website by accessing a specially crafted URL. As a result, the user may become a victim of a phishi…
- CVE-2023-22641MEDIUMCVSS 4.1EG 5.42023-04-11
A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiPro…
- CVE-2023-22729MEDIUMCVSS 5.4EG 5.42023-04-26
Silverstripe Framework is the Model-View-Controller framework that powers the Silverstripe content management system. Prior to version 4.12.15, an attacker can display a link to a third party website on a login screen by convincing a legit…
- CVE-2023-22797MEDIUMCVSS 6.1EG 6.12023-02-09
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted in…
- CVE-2023-22798MEDIUMCVSS 6.1EG 6.12023-02-09
Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may have been there for security purposes. This…
- CVE-2023-22958MEDIUMCVSS 6.1EG 6.12023-01-11
The Syracom Secure Login plugin before 3.1.1.0 for Jira may allow spoofing of 2FA PIN validation via the plugins/servlet/twofactor/public/pinvalidation target parameter.
- CVE-2023-23395LOWCVSS 3.1EG 3.12023-03-14
Microsoft SharePoint Server Spoofing Vulnerability
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →