← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openmrs
1Openmrs
Jun 17, 2026
Apr 17, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of potentially sensitiv...Show more
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows the export of potentially sensitive information.Show less
1Openmrs
1Openmrs
Jun 17, 2026
Apr 17, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feat...Show more
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user attempts to access it. This allows unauthenticated users to use a feature typically restricted to administrators.Show less
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier handles loginRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier handles homeRedirect page redirects in an insecure manner, which allows attackers to perform open redirect attacks.
1Broadcom
1Ca Api Developer Portal
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
CA API Developer Portal 4.3.1 and earlier handles 404 requests in an insecure manner, which allows attackers to perform open redirect attacks.
1Vmware
1Vrealize Log Insight
Jun 17, 2026
Apr 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open Redirect vulnerability exists in VMware vRealize Log Insight prior to 8.1.0 due to improper Input validation.
1Sap
1Netweaver As Abap Business Server Pages
Jun 17, 2026
Apr 14, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validati...Show more
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Apr 14, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leadin...Show more
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.Show less
1Sap
1Businessobjects Business Intelligence Platform
Jun 17, 2026
Apr 14, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into ac...Show more
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content. This can misdirect a user who is tricked into accessing these error pages rendered by the application, leading to Content Spoofing.Show less
1Stormshield
1Stormshield Network Security
Jun 17, 2026
Apr 13, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in...Show more
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal. For example, the attacker can use rurl=//example.com instead of rurl=https://example.com in the query string.Show less
1Cross Domain Local Storage Project
1Cross Domain Local Storage
Jun 17, 2026
Apr 7, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. There...Show more
An issue was discovered in xdLocalStorage through 2.0.5. The buildMessage() function in xdLocalStorage.js specifies the wildcard (*) as the targetOrigin when calling the postMessage() function on the iframe object. Therefore any domain that is currently loaded within the iframe can receive the messages that the client sends.Show less
1Rankmath
1Seo
Jun 17, 2026
Apr 7, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In...Show more
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint. In other words, this is not an "Open Redirect" issue; instead, it allows the attacker to create a new URI with an arbitrary name (e.g., the /exampleredirect URI).Show less
1Getgrav
1Grav
Jun 17, 2026
Apr 4, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Common/Grav.php in Grav before 1.7 has an Open Redirect. This is partially fixed in 1.6.23 and still present in 1.6.x.
1Revive Adserver
1Revive Adserver
Jun 17, 2026
Apr 3, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them r...Show more
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144. A remote attacker could trick logged-in users to open a specifically crafted link and have them redirected to any destination.The CSRF protection of the “/www/admin/*-modify.php” could be skipped if no meaningful parameter was sent. No action was performed, but the user was still redirected to the target page, specified via the “returnurl” GET parameter.Show less
8Apache
BroadcomCanonical+5 more
14Brocade Fabric Operating System
Communications Element ManagerCommunications Session Report Manager+11 more
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.Show less
1Centreon
1Centreon
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.
1Moodle
1Moodle
Jun 17, 2026
Mar 18, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed in the Lesson edit page.
1Halvotec
1Raquest
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.2 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication...Show more
An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify the victim's request on the wire. Fixed in Release 24.2020.20608.0Show less
1Fortinet
1Fortios
Jun 17, 2026
Mar 15, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin in...Show more
An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.Show less
1Mozilla
1Webthings Gateway
Jun 17, 2026
Feb 28, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.