CWE-601— URL Redirection to Untrusted Site (Open Redirect)
1,356 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-601page 6 of 28
- CVE-2020-1059MEDIUMCVSS 4.3EG 4.32020-05-21
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka 'Microsoft Edge Spoofing Vulnerability'.
- CVE-2020-10775MEDIUMCVSS 5.3EG 5.32020-08-24
An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the malicious URL in thei…
- CVE-2020-10959MEDIUMCVSS 6.1EG 6.12020-06-02
resources/src/mediawiki.page.ready/ready.js in MediaWiki before 1.35 allows remote attackers to force a logout and external redirection via HTML content in a MediaWiki page.
- CVE-2020-11034MEDIUMCVSS 6.1EG 6.12020-05-05
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6.
- CVE-2020-11053HIGHCVSS 7.1EG 7.12020-05-07
In OAuth2 Proxy before 5.1.1, there is an open redirect vulnerability. Users can provide a redirect address for the proxy to send the authenticated user to at the end of the authentication flow. This is expected to be the original URL that…
- CVE-2020-11515MEDIUMCVSS 6.1EG 6.12020-04-07
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this …
- CVE-2020-11529MEDIUMCVSS 6.1EG 6.12020-04-04
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
- CVE-2020-11611MEDIUMCVSS 6.1EG 6.12020-04-07
An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. Therefore any domain tha…
- CVE-2020-11663MEDIUMCVSS 6.1EG 6.12020-04-15
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
- CVE-2020-11664MEDIUMCVSS 6.1EG 6.12020-04-15
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
- CVE-2020-11665MEDIUMCVSS 6.1EG 6.12020-04-15
CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
- CVE-2020-11882MEDIUMCVSS 6.1EG 6.12020-07-07
The O2 Business application 1.2.0 for Android exposes the canvasm.myo2.SplashActivity activity to other applications. The purpose of this activity is to handle deeplinks that can be delivered either via links or by directly calling the act…
- CVE-2020-1220MEDIUMCVSS 6.1EG 6.12020-06-09
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
- CVE-2020-12283MEDIUMCVSS 6.1EG 6.12020-04-30
Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring.
- CVE-2020-12483HIGHCVSS 8.2EG 8.22021-03-23
The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.
- CVE-2020-12666MEDIUMCVSS 6.1EG 6.12020-05-05
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.
- CVE-2020-12699MEDIUMCVSS 6.1EG 6.12020-05-13
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
- CVE-2020-13121MEDIUMCVSS 6.1EG 6.12020-05-16
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
- CVE-2020-1323MEDIUMCVSS 6.1EG 6.12020-06-09
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint…
- CVE-2020-13486MEDIUMCVSS 6.1EG 6.12020-05-25
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
- CVE-2020-13565MEDIUMCVSS 6.1EG 6.12021-02-10
An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request ca…
- CVE-2020-13662MEDIUMCVSS 6.1EG 6.12021-05-05
Open Redirect vulnerability in Drupal Core allows a user to be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL. This issue affects: Drupal Drupal Core 7 version 7.70 and prior versions.
- CVE-2020-14118MEDIUMCVSS 6.1EG 6.12022-04-21
An intent redirection vulnerability in the Mi App Store product. This vulnerability is caused by the Mi App Store does not verify the validity of the incoming data, can cause the app store to automatically download and install apps.
- CVE-2020-14446MEDIUMCVSS 6.1EG 6.12020-06-18
An issue was discovered in WSO2 Identity Server through 5.10.0 and WSO2 IS as Key Manager through 5.10.0. An open redirect exists.
- CVE-2020-14454MEDIUMCVSS 6.1EG 6.12020-06-19
An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
- CVE-2020-15129MEDIUMCVSS 6.1EG 6.12020-07-30
In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of …
- CVE-2020-15233MEDIUMCVSS 6.1EG 6.12020-10-02
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite from version 0.30.2 and before version 0.34.1, there is an issue in which an an attacker can override the registered redirect URL by performing an OAuth flo…
- CVE-2020-15234MEDIUMCVSS 6.1EG 6.12020-10-02
ORY Fosite is a security first OAuth2 & OpenID Connect framework for Go. In Fosite before version 0.34.1, the OAuth 2.0 Client's registered redirect URLs and the redirect URL provided at the OAuth2 Authorization Endpoint where compared usi…
- CVE-2020-15241MEDIUMCVSS 4.7EG 4.72020-10-08
TYPO3 Fluid Engine (package `typo3fluid/fluid`) before versions 2.0.5, 2.1.4, 2.2.1, 2.3.5, 2.4.1, 2.5.5 or 2.6.1 is vulnerable to cross-site scripting when making use of the ternary conditional operator in templates like `{showFullName ? …
- CVE-2020-15242MEDIUMCVSS 4.7EG 4.72020-10-08
Next.js versions >=9.5.0 and <9.5.4 are vulnerable to an Open Redirect. Specially encoded paths could be used with the trailing slash redirect to allow an open redirect to occur to an external site. In general, this redirect does not direc…
- CVE-2020-15300MEDIUMCVSS 6.1EG 6.12020-11-18
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
- CVE-2020-15677MEDIUMCVSS 6.1EG 6.12020-10-01
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was…
- CVE-2020-1723MEDIUMCVSS 6.1EG 4.32021-01-28
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
- CVE-2020-17484MEDIUMCVSS 6.1EG 6.12023-12-16
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
- CVE-2020-18268MEDIUMCVSS 6.1EG 6.12021-06-07
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
- CVE-2020-18660MEDIUMCVSS 6.1EG 6.12021-06-23
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
- CVE-2020-18985MEDIUMCVSS 6.1EG 6.12021-12-15
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
- CVE-2020-1927MEDIUMCVSS 6.1EG 6.12020-04-02
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
- CVE-2020-1997MEDIUMCVSS 5.3EG 5.32020-05-13
An open redirection vulnerability in the GlobalProtect component of Palo Alto Networks PAN-OS allows an attacker to specify an arbitrary redirection target away from the trusted GlobalProtect gateway. If the user then successfully authenti…
- CVE-2020-21038MEDIUMCVSS 6.1EG 6.12023-05-08
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
- CVE-2020-21998MEDIUMCVSS 6.1EG 6.12021-04-27
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user click…
- CVE-2020-22840MEDIUMCVSS 6.1EG 6.12021-02-09
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
- CVE-2020-23015MEDIUMCVSS 6.1EG 6.12021-05-03
An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.
- CVE-2020-23182MEDIUMCVSS 5.4EG 5.42021-07-02
The component /php-fusion/infusions/shoutbox_panel/shoutbox_archive.php in PHP-Fusion 9.03.60 allows attackers to redirect victim users to malicious websites via a crafted payload entered into the Shoutbox message panel.
- CVE-2020-24550MEDIUMCVSS 6.1EG 6.12021-03-31
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.
- CVE-2020-24551MEDIUMCVSS 6.1EG 6.12020-10-14
IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login credentials.
- CVE-2020-24554HIGHCVSS 7.5EG 7.52020-09-01
The redirect module in Liferay Portal before 7.3.3 does not limit the number of URLs resulting in a 404 error that is recorded, which allows remote attackers to perform a denial of service attack by making repeated requests for pages that …
- CVE-2020-24598MEDIUMCVSS 6.1EG 6.12020-08-26
An issue was discovered in Joomla! before 3.9.21. Lack of input validation in the vote feature of com_content leads to an open redirect.
- CVE-2020-25154MEDIUMCVSS 5.4EG 6.12022-04-14
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious w…
- CVE-2020-25845HIGHCVSS 7.5EG 7.52020-12-31
Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.
Map vulnerabilities like CWE-601 to your infrastructure
EchelonGraph correlates every CVE — across CWE-601 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →