CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,636 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 20 of 33
- CVE-2024-21065MEDIUMCVSS 6.1EG 6.12024-04-16
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker wit…
- CVE-2024-21497MEDIUMCVSS 5.4EG 5.42024-02-17
Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convinc…
- CVE-2024-21641MEDIUMCVSS 4.7EG 4.72024-01-05
Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redirect parameter that allows any third party to redirect users from a (trusted) domain of the Flarum installation to redire…
- CVE-2024-21684MEDIUMCVSS 4.3EG 4.32024-07-24
There is a low severity open redirect vulnerability within affected versions of Bitbucket Data Center. Versions of Bitbucket DC from 8.0.0 to 8.9.12 and 8.19.0 to 8.19.1 are affected by this vulnerability. It is patched in 8.9.13 and 8.19.…
- CVE-2024-21723MEDIUMCVSS 4.3EG 4.32024-02-29
Inadequate parsing of URLs could result into an open redirect.
- CVE-2024-21728MEDIUMCVSS 6.1EG 6.12024-02-15
An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x extension that provides Joomla fronted integration with osTicket, a popular Support ticket system. The Open Redirect v…
- CVE-2024-21734MEDIUMCVSS 5.4EG 5.42024-01-09
SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious page which could lead to a very convincing phishing attack with low impact on confidentiality and integrity of the applica…
- CVE-2024-21794MEDIUMCVSS 5.4EG 5.42024-02-02
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.
- CVE-2024-22113MEDIUMCVSS 6.1EG 6.12024-01-22
Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary websites and conduct phishing attacks via a specially crafted U…
- CVE-2024-22243HIGHCVSS 8.1EG 8.12024-02-23
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/…
- CVE-2024-22244MEDIUMCVSS 4.3EG 4.32024-06-10
Open Redirect in Harbor <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.
- CVE-2024-22248HIGHCVSS 7.1EG 7.12024-04-02
VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled domain due to improper path handling leading to sensitive information disclosure.
- CVE-2024-22259HIGHCVSS 8.1EG 8.12024-03-16
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https:/…
- CVE-2024-22262HIGHCVSS 8.1EG 8.12024-04-16
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/…
- CVE-2024-22308LOWCVSS 3.4EG 3.42024-01-24
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.
- CVE-2024-22400LOWCVSS 3.1EG 3.12024-01-18
Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is…
- CVE-2024-22854MEDIUMCVSS 6.1EG 6.12024-02-16
DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61050) and before has been identified. A URL, crafted by a remote attacker and visited by an authenticated user, allows o…
- CVE-2024-22891CRITICALCVSS 9.8EG 9.82024-03-01
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
- CVE-2024-23442MEDIUMCVSS 6.1EG 6.12024-06-14
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously crafted Kibana URL.
- CVE-2024-23664MEDIUMCVSS 6.1EG 6.12024-06-03
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.
- CVE-2024-24034MEDIUMCVSS 6.1EG 6.12024-02-08
Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers to execute arbitrary code.
- CVE-2024-2419HIGHCVSS 7.1EG 7.12024-04-17
A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to the theft of an access token, making it possible for the attacker to imperso…
- CVE-2024-24291MEDIUMCVSS 6.1EG 6.12024-02-06
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
- CVE-2024-2465HIGHCVSS 7.1EG 7.12024-03-21
Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.
- CVE-2024-24763MEDIUMCVSS 4.3EG 4.32024-02-20
JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to construct malicious links, leading users to click on them, thereby facil…
- CVE-2024-24764LOWCVSS 3.5EG 3.52024-06-26
October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema …
- CVE-2024-24808MEDIUMCVSS 4.7EG 4.72024-02-06
pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting users after login. pyLoad is validating URLs via the `get_redirect_url` …
- CVE-2024-24818MEDIUMCVSS 5.9EG 5.92024-03-21
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. T…
- CVE-2024-25559MEDIUMCVSS 4.7EG 4.72024-02-15
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
- CVE-2024-25566MEDIUMCVSS 6.1EG 6.12024-10-29
An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to malicious sites under their control, simplifying phishing att…
- CVE-2024-25608MEDIUMCVSS 6.1EG 6.12024-02-20
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix pack 19, and older unsupported versions can be circumvented by usin…
- CVE-2024-25609MEDIUMCVSS 6.1EG 6.12024-02-20
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack 15 through 18, and older unsupported versions can be circumvented by us…
- CVE-2024-25657MEDIUMCVSS 5.4EG 5.42024-03-18
An open redirect in the Login/Logout functionality of web management in AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS could allow attackers to redirect authenticated users to malicious websites.
- CVE-2024-25676MEDIUMCVSS 4.7EG 4.72024-05-01
An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanitizing it. This leads to both open redirection and out-of-band resource loading.
- CVE-2024-25715MEDIUMCVSS 6.1EG 6.12024-02-11
Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.
- CVE-2024-26504HIGHCVSS 8.8EG 8.82024-05-01
An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter.
- CVE-2024-27184MEDIUMCVSS 6.1EG 6.12024-08-20
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
- CVE-2024-27291MEDIUMCVSS 6.1EG 6.12024-03-21
Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a URL that acts as an open redirect. The vulnerability has been patched in version 1.4.97 of the master branch.
- CVE-2024-27592MEDIUMCVSS 4.3EG 4.32024-04-11
Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.
- CVE-2024-28076HIGHCVSS 7.0EG 7.02024-04-18
The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format
- CVE-2024-28113LOWCVSS 3.5EG 3.52024-03-12
Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arbitrary page using a crafted url. As a result users can be redirected to an unexpected location. This issue has been add…
- CVE-2024-28239MEDIUMCVSS 5.4EG 5.42024-03-12
Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect` parameter that can be exploited as an open redirect vulnerability as the user tries to log in via the API URL. There's…
- CVE-2024-28287HIGHCVSS 7.3EG 7.32024-04-02
A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.
- CVE-2024-28344LOWCVSS 3.1EG 3.12024-04-10
An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.
- CVE-2024-29041MEDIUMCVSS 6.1EG 6.12024-03-25
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a …
- CVE-2024-30140MEDIUMCVSS 5.4EG 5.42024-11-07
HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can poison the web cache and provide back to users being served the page.
- CVE-2024-3032MEDIUMCVSS 6.1EG 6.12024-06-13
Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
- CVE-2024-31135MEDIUMCVSS 6.1EG 6.12024-03-28
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
- CVE-2024-31213LOWCVSS 3.5EG 3.52024-04-05
InstantCMS is a free and open source content management system. An open redirect was found in the ICMS2 application version 2.16.2 when being redirected after modifying one's own user profile. An attacker could trick a victim into visiting…
- CVE-2024-31253MEDIUMCVSS 4.7EG 4.72024-04-10
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →