CWE-601— URL Redirection to Untrusted Site (Open Redirect)
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.— MITRE CWE catalog
1,627 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 4 of 33
- CVE-2017-3840MEDIUMCVSS 6.1EG 6.12017-02-22
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. More Information: CSCvc048…
- CVE-2017-3889MEDIUMCVSS 6.1EG 6.12017-04-07
A vulnerability in the web interface of the Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to redirect a user to a undesired web page, aka an Open Redirect. This vulnerability affects the Cisco Registered…
- CVE-2017-5002MEDIUMCVSS 6.1EG 6.12017-07-07
EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an open redirect vulnerability. A remote unprivileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks…
- CVE-2017-5389MEDIUMCVSS 6.1EG 6.12018-06-11
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then i…
- CVE-2017-5474MEDIUMCVSS 6.1EG 6.12017-01-14
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
- CVE-2017-5571MEDIUMCVSS 6.1EG 6.12017-03-03
Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to re…
- CVE-2017-5614MEDIUMCVSS 6.1EG 6.12017-03-03
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter.
- CVE-2017-5615MEDIUMCVSS 6.1EG 6.12017-03-03
cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.
- CVE-2017-5871MEDIUMCVSS 5.4EG 5.42019-05-22
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
- CVE-2017-6018MEDIUMCVSS 6.1EG 6.12017-06-30
An open redirect issue was discovered in B. Braun Medical SpaceCom module, which is integrated into the SpaceStation docking station: SpaceStation with SpaceCom module (integrated as part number 8713142U), software versions prior to Versio…
- CVE-2017-6604MEDIUMCVSS 6.1EG 6.12017-04-07
A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco produc…
- CVE-2017-6670MEDIUMCVSS 6.1EG 6.12017-06-13
A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known…
- CVE-2017-6932MEDIUMCVSS 4.7EG 4.72018-03-01
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacke…
- CVE-2017-7153MEDIUMCVSS 6.1EG 6.12018-04-03
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS …
- CVE-2017-7233MEDIUMCVSS 6.1EG 6.12017-04-04
Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) conside…
- CVE-2017-7234MEDIUMCVSS 6.1EG 6.12017-04-04
A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.
- CVE-2017-7266MEDIUMCVSS 6.1EG 6.12017-03-26
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
- CVE-2017-7343MEDIUMCVSS 6.1EG 6.12017-05-27
An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.
- CVE-2017-8047MEDIUMCVSS 6.1EG 6.12017-10-04
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. A…
- CVE-2017-8451MEDIUMCVSS 6.1EG 6.12017-06-16
With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.
- CVE-2017-8621MEDIUMCVSS 6.1EG 6.12017-07-11
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".
- CVE-2017-8945MEDIUMCVSS 6.1EG 6.12018-02-15
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.
- CVE-2017-8989CRITICALCVSS 9.1EG 9.12018-08-06
A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.
- CVE-2017-9062HIGHCVSS 8.6EG 8.62017-05-18
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.
- CVE-2017-9296MEDIUMCVSS 6.1EG 6.12017-05-29
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Tuning Manager before 8.5.2-00 allows remote attackers to redirect authenticated users to arbitrary web sites.
- CVE-2017-9297MEDIUMCVSS 6.1EG 6.12017-05-29
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites.
- CVE-2017-9464MEDIUMCVSS 6.1EG 6.12017-06-14
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issu…
- CVE-2018-0097MEDIUMCVSS 6.1EG 6.12018-01-18
A vulnerability in the web interface of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect. The vulnerability is due to improper input validation of t…
- CVE-2018-0688MEDIUMCVSS 6.1EG 6.12019-01-09
Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 Septem…
- CVE-2018-0924MEDIUMCVSS 6.5EG 6.52018-03-14
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Ser…
- CVE-2018-1000174MEDIUMCVSS 6.1EG 6.12018-05-08
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
- CVE-2018-1000504HIGHCVSS 7.2EG 7.22018-06-26
Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This attack appear to be exploitable via Attacker must be have acces…
- CVE-2018-1000671MEDIUMCVSS 6.1EG 6.12018-09-06
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via dat…
- CVE-2018-1002102LOWCVSS 2.6EG 2.62019-12-05
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will f…
- CVE-2018-10100MEDIUMCVSS 6.1EG 6.12018-04-16
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
- CVE-2018-10101MEDIUMCVSS 6.1EG 6.12018-04-16
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
- CVE-2018-10651MEDIUMCVSS 6.1EG 6.12018-05-23
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
- CVE-2018-10678MEDIUMCVSS 6.1EG 6.12018-05-13
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
- CVE-2018-11041MEDIUMCVSS 6.1EG 6.12018-06-25
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for in…
- CVE-2018-11067MEDIUMCVSS 6.1EG 6.12018-11-26
Dell EMC Avamar Client Manager in Dell EMC Avamar Server versions 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.4.0, 7.4.1, 7.5.0, 7.5.1, 18.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 and 2.2 contain an open redirection v…
- CVE-2018-11119MEDIUMCVSS 6.1EG 6.12018-05-17
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
- CVE-2018-11408MEDIUMCVSS 6.1EG 6.12018-06-13
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlin…
- CVE-2018-11784CRITICALCVSS 4.3EG 9.02018-10-04
When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be us…
- CVE-2018-1220MEDIUMCVSS 6.1EG 6.12018-03-08
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the intent of obtainin…
- CVE-2018-12300MEDIUMCVSS 6.1EG 6.12019-05-13
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
- CVE-2018-1248MEDIUMCVSS 6.1EG 6.12018-05-08
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and…
- CVE-2018-1251HIGHCVSS 8.3EG 8.32018-09-28
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricki…
- CVE-2018-12621MEDIUMCVSS 6.1EG 6.12019-07-05
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
- CVE-2018-12675MEDIUMCVSS 6.1EG 6.12018-10-19
The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpect…
- CVE-2018-13257MEDIUMCVSS 6.1EG 6.12019-11-18
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS se…
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →