CWE-601— URL Redirection to Untrusted Site (Open Redirect)
1,355 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 2 of 28
- CVE-2017-1668MEDIUMCVSS 6.1EG 6.12018-01-09
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this…
- CVE-2017-1748MEDIUMCVSS 6.8EG 6.12018-06-04
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to…
- CVE-2017-18109MEDIUMCVSS 6.1EG 6.12019-03-29
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack v…
- CVE-2017-18178MEDIUMCVSS 6.1EG 6.12018-02-12
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
- CVE-2017-18262MEDIUMCVSS 6.1EG 6.12018-04-30
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/s…
- CVE-2017-18414HIGHCVSS 7.4EG 7.42019-08-02
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
- CVE-2017-18441MEDIUMCVSS 5.0EG 5.02019-08-02
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
- CVE-2017-18891MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
- CVE-2017-18897MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
- CVE-2017-20119LOWCVSS 3.5EG 6.12022-06-29
A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to…
- CVE-2017-20164MEDIUMCVSS 6.3EG 6.32023-01-07
A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onBeforeSecurityLogin of the file code/extensions/SecurityLoginExtension.php of the component Login. The manipulation of t…
- CVE-2017-2166MEDIUMCVSS 6.1EG 6.12018-01-26
Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2017-5389MEDIUMCVSS 6.1EG 6.12018-06-11
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then i…
- CVE-2017-5871MEDIUMCVSS 5.4EG 5.42019-05-22
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
- CVE-2017-6932MEDIUMCVSS 4.7EG 4.72018-03-01
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacke…
- CVE-2017-7153MEDIUMCVSS 6.1EG 6.12018-04-03
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS …
- CVE-2017-8945MEDIUMCVSS 6.1EG 6.12018-02-15
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.
- CVE-2017-8989CRITICALCVSS 9.1EG 9.12018-08-06
A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.
- CVE-2018-0097MEDIUMCVSS 6.1EG 6.12018-01-18
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of t…
- CVE-2018-0688MEDIUMCVSS 6.1EG 6.12019-01-09
Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 Septem…
- CVE-2018-0924MEDIUMCVSS 6.5EG 6.52018-03-14
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Ser…
- CVE-2018-1000174MEDIUMCVSS 6.1EG 6.12018-05-08
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
- CVE-2018-1000504HIGHCVSS 7.2EG 7.22018-06-26
Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This attack appear to be exploitable via Attacker must be have acces…
- CVE-2018-1000671MEDIUMCVSS 6.1EG 6.12018-09-06
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via dat…
- CVE-2018-1002102LOWCVSS 2.6EG 2.62019-12-05
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will f…
- CVE-2018-10100MEDIUMCVSS 6.1EG 6.12018-04-16
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
- CVE-2018-10101MEDIUMCVSS 6.1EG 6.12018-04-16
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
- CVE-2018-10651MEDIUMCVSS 6.1EG 6.12018-05-23
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- CVE-2018-10678MEDIUMCVSS 6.1EG 6.12018-05-13
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
- CVE-2018-11041MEDIUMCVSS 6.1EG 6.12018-06-25
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for in…
- CVE-2018-11067MEDIUMCVSS 6.1EG 6.12018-11-26
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection v…
- CVE-2018-11119MEDIUMCVSS 6.1EG 6.12018-05-17
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
- CVE-2018-11408MEDIUMCVSS 6.1EG 6.12018-06-13
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlin…
- CVE-2018-11784MEDIUMCVSS 4.3EG 4.32018-10-04
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be us…
- CVE-2018-1220MEDIUMCVSS 6.1EG 6.12018-03-08
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the intent of obtainin…
- CVE-2018-12300MEDIUMCVSS 6.1EG 6.12019-05-13
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
- CVE-2018-1248MEDIUMCVSS 6.1EG 6.12018-05-08
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and…
- CVE-2018-1251HIGHCVSS 8.3EG 8.12018-09-28
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricki…
- CVE-2018-12621MEDIUMCVSS 6.1EG 6.12019-07-05
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
- CVE-2018-12675MEDIUMCVSS 6.1EG 6.12018-10-19
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpect…
- CVE-2018-13257MEDIUMCVSS 6.1EG 6.12019-11-18
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS se…
- CVE-2018-13384MEDIUMCVSS 6.1EG 6.12019-06-04
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web dom…
- CVE-2018-13401MEDIUMCVSS 6.1EG 6.12018-10-23
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from…
- CVE-2018-13402MEDIUMCVSS 6.1EG 6.12018-10-23
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3, from version 7.11.…
- CVE-2018-1355MEDIUMCVSS 6.1EG 6.12018-06-27
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiVi…
- CVE-2018-13813HIGHCVSS 8.1EG 8.12018-12-13
A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V15 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KT…
- CVE-2018-14366MEDIUMCVSS 6.1EG 6.12018-09-06
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
- CVE-2018-14381MEDIUMCVSS 6.1EG 6.12018-07-18
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
- CVE-2018-14398MEDIUMCVSS 6.1EG 6.12018-09-07
An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.
- CVE-2018-14474MEDIUMCVSS 6.1EG 6.12018-07-20
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →