CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Ope...Show more |
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before version 7.10.3,...Show more |
The XsrfErrorAction resource in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 before v...Show more |
1Sv3c 1H.264 Poe Ip Camera Firmware Nov 21, 2024 Oct 19, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a...Show more |
vBulletin 5.4.3 has an Open Redirect. |
1Cisco 4Emergency Responder Unified Communications ManagerUnified Communications Manager Im And Presence Service+1 moreNov 21, 2024 Oct 5, 2018 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated...Show more |
6Apache CanonicalDebian+3 more15Communications Application Session Controller Debian LinuxEnterprise Linux Desktop+12 moreNov 21, 2024 Oct 4, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially craf...Show more |
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683. |
1Dell 2Emc Unity Firmware Emc UnityvsaNov 21, 2024 Sep 28, 2018 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary...Show more |
1Ibm 2Platform Symphony Spectrum SymphonyNov 21, 2024 Sep 28, 2018 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a speci...Show more |
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could...Show more |
1Oracle 1Webcenter Interaction Nov 21, 2024 Sep 18, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parameter is not validated...Show more |
1Feed Statistics Project 1Feed Statistics Nov 21, 2024 Sep 16, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. |
1F5 1Big Ip Access Policy Manager Jun 17, 2026 Sep 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 On BIG-IP APM 11.6.0-11.6.3, an insecure AES ECB mode is used for orig_uri parameter in an undisclosed /vdesk link of APM virtual server configured with an access profile, allowing a malicious user to build a redirect UR...Show more |
Eventum before 3.4.0 has an open redirect vulnerability. |
An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials. |
2Ivanti Pulsesecure3Connect Secure Pulse Connect SecurePulse Policy SecureNov 21, 2024 Sep 6, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability. |
2Debian Sympa2Debian Linux SympaNov 21, 2024 Sep 6, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and re...Show more |
An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be ins...Show more |
3Debian GoogleRedhat5Chrome Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Aug 28, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page. |