CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,627 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 3 of 33
- CVE-2017-1159MEDIUMCVSS 5.4EG 5.42017-05-22
IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerabi…
- CVE-2017-11718MEDIUMCVSS 6.1EG 6.12017-07-28
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php.
- CVE-2017-11725MEDIUMCVSS 5.4EG 5.42017-07-29
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
- CVE-2017-11879HIGHCVSS 8.8EG 8.82017-11-15
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".
- CVE-2017-1195MEDIUMCVSS 6.1EG 6.12017-08-29
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could expl…
- CVE-2017-12138MEDIUMCVSS 6.1EG 6.12017-08-02
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
- CVE-2017-1223MEDIUMCVSS 6.1EG 6.12017-07-19
IBM Tivoli Endpoint Manager could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof…
- CVE-2017-12344MEDIUMCVSS 6.1EG 6.12017-11-30
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content int…
- CVE-2017-1287MEDIUMCVSS 5.4EG 5.42017-07-24
IBM Rhapsody DM 5.0 and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof…
- CVE-2017-1398MEDIUMCVSS 6.1EG 6.12017-07-10
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web sit…
- CVE-2017-14038MEDIUMCVSS 6.1EG 6.12017-08-30
CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.
- CVE-2017-14358MEDIUMCVSS 6.1EG 6.12017-10-31
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untr…
- CVE-2017-14394MEDIUMCVSS 6.1EG 6.12019-06-19
OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to perform phishing via …
- CVE-2017-1448MEDIUMCVSS 5.4EG 5.42017-08-09
IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could ex…
- CVE-2017-1449MEDIUMCVSS 5.4EG 5.42017-08-31
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability t…
- CVE-2017-1450MEDIUMCVSS 6.1EG 6.12017-08-31
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability t…
- CVE-2017-14524MEDIUMCVSS 6.1EG 6.12017-09-28
Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/de…
- CVE-2017-14525MEDIUMCVSS 6.1EG 6.12017-09-28
Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.h…
- CVE-2017-14725MEDIUMCVSS 5.4EG 5.42017-09-23
Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.
- CVE-2017-14802MEDIUMCVSS 5.4EG 6.12018-03-02
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.
- CVE-2017-1489MEDIUMCVSS 6.1EG 6.12017-08-29
IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128…
- CVE-2017-1534MEDIUMCVSS 6.1EG 6.12018-01-10
IBM Security Access Manager Appliance 8.0.0 and 9.0.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit t…
- CVE-2017-15419MEDIUMCVSS 6.5EG 6.52018-08-28
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
- CVE-2017-1558MEDIUMCVSS 6.1EG 6.12017-12-13
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerabil…
- CVE-2017-16224MEDIUMCVSS 6.1EG 6.12018-06-07
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to…
- CVE-2017-16569MEDIUMCVSS 4.8EG 4.82017-11-06
An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
- CVE-2017-16652MEDIUMCVSS 6.1EG 6.12018-06-13
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path par…
- CVE-2017-16679MEDIUMCVSS 6.1EG 6.12017-12-12
URL redirection vulnerability in SAP's Startup Service, SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.52, that allows an attacker…
- CVE-2017-1668MEDIUMCVSS 6.1EG 6.12018-01-09
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this…
- CVE-2017-16761MEDIUMCVSS 6.1EG 6.12017-11-10
An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.
- CVE-2017-1748MEDIUMCVSS 6.8EG 6.82018-06-04
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to…
- CVE-2017-18109MEDIUMCVSS 6.1EG 6.12019-03-29
The login resource of CrowdId in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack v…
- CVE-2017-18178MEDIUMCVSS 6.1EG 6.12018-02-12
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
- CVE-2017-18262MEDIUMCVSS 6.1EG 6.12018-04-30
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/s…
- CVE-2017-18414HIGHCVSS 7.4EG 7.42019-08-02
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
- CVE-2017-18441MEDIUMCVSS 5.0EG 5.02019-08-02
cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
- CVE-2017-18891MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows Phishing because an error page can have a link.
- CVE-2017-18897MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. It mishandles a deny action for a redirection.
- CVE-2017-20119MEDIUMCVSS 3.5EG 6.12022-06-29
A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to…
- CVE-2017-20164MEDIUMCVSS 6.3EG 6.32023-01-07
A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onBeforeSecurityLogin of the file code/extensions/SecurityLoginExtension.php of the component Login. The manipulation of t…
- CVE-2017-2166MEDIUMCVSS 6.1EG 6.12018-01-26
Open redirect vulnerability in GroupSession version 4.7.0 and earlier allows an attacker to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2017-2217MEDIUMCVSS 6.1EG 6.12017-07-07
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
- CVE-2017-2404HIGHCVSS 3.3EG 7.52017-04-02
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "Quick Look" component. It allows remote attackers to trigger telephone calls to arbitrary numbers via a tel: URL in a PDF document, as …
- CVE-2017-2497MEDIUMCVSS 6.1EG 6.12017-05-22
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "iBooks" component. It allows remote attackers to trigger visits to arbitrary URLs via a crafted boo…
- CVE-2017-3085HIGHCVSS 7.4EG 7.52017-08-11
Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.
- CVE-2017-3105MEDIUMCVSS 6.1EG 6.12017-12-01
Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.
- CVE-2017-3126MEDIUMCVSS 6.1EG 6.12017-05-27
An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter.
- CVE-2017-3528MEDIUMCVSS 5.4EG 5.42017-04-24
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. …
- CVE-2017-3799MEDIUMCVSS 5.4EG 5.42017-01-26
A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1.
- CVE-2017-3810MEDIUMCVSS 5.4EG 5.42017-02-03
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Kno…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →