CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Optergy Proton/Enterprise devices allow Open Redirect. |
4Canonical FedoraprojectMod Auth Mellon Project+1 more4Fedora Mod Auth MellonUbuntu Linux+1 moreJun 17, 2026 Jun 29, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Jun 27, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs. |
IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker co...Show more |
1Forgerock 2Access Management OpenamNov 21, 2024 Jun 19, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 OAuth 2.0 Authorization Server of ForgeRock Access Management (OpenAM) 13.5.0-13.5.1 and Access Management (AM) 5.0.0-5.1.1 does not correctly validate redirect_uri for some invalid requests, which allows attackers to pe...Show more |
2Oracle Pivotal Software2Banking Corporate Lending Spring Security OauthJun 17, 2026 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an...Show more |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Jun 7, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect. |
1Ibm 1Jazz For Service Management Jun 17, 2026 Jun 6, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote...Show more |
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users t...Show more |
1Samsung 1Galaxy S9 Firmware Jun 17, 2026 Jun 3, 2019 N/A· v4 9.3 CRITICAL· v3 5.8 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security Update (SMR-JAN-2019 - SVE-2018-13467). User interaction is required to...Show more |
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote). |
An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially...Show more |
Open redirect vulnerability in Cybozu Garoon 4.2.4 to 4.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the Login Screen. |
An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:Ge...Show more |
1Bosch 4Divar Ip 2000 Firmware Divar Ip 5000 FirmwareVideo Management System+1 moreJun 17, 2026 May 13, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote attacker to redirect users to an arbitrary URL. Affected hardwar...Show more |
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter. |
1Revive Adserver 1Revive Adserver Jun 17, 2026 May 6, 2019 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted admin account-switch.php URL that would eventually lead them to another (unsafe) domain, potentially u...Show more |
1Polarisft 1Intellect Core Banking Nov 21, 2024 Apr 30, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI. |
IBM StoredIQ 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability...Show more |