← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Url Parse Project
1Url Parse
Nov 21, 2024
Aug 12, 2018
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
1Microfocus
1Edirectory
Jun 17, 2026
Aug 9, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.
1Gogs
1Gogs
Nov 21, 2024
Aug 8, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to...Show more
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.Show less
1Hp
1Xp 9000 Command View
Jun 17, 2026
Aug 6, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
HPE XP P9000 Command View Advanced Edition Software (CVAE) has open URL redirection vulnerability in versions 7.0.0-00 to earlier than 8.60-00 of DevMgr, TSMgr and RepMgr.
1Hp
1Icewall Sso
Nov 21, 2024
Aug 6, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.
3Canonical
DebianDjangoproject
3Debian Linux
DjangoUbuntu Linux
Nov 21, 2024
Aug 3, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
django.middleware.common.CommonMiddleware in Django 1.11.x before 1.11.15 and 2.0.x before 2.0.8 has an Open Redirect.
1Goodoldweb
1Orange Forum
Nov 21, 2024
Jul 20, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
1Pagekit
1Pagekit
Nov 21, 2024
Jul 18, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
1Ibm
1Inotes
Nov 21, 2024
Jul 11, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID...Show more
Open redirect vulnerability in IBM iNotes before 8.5.3 Fix Pack 6 and 9.x before 9.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. IBM X-Force ID: 83383.Show less
1Fortinet
2Fortianalyzer
Fortimanager
Nov 21, 2024
Jun 27, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF documen...Show more
An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.Show less
1Redirection
1Redirection
Nov 21, 2024
Jun 26, 2018
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This attack appear to be exploitable via Attacker...Show more
Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows admins to execute any PHP file in the filesystem. This attack appear to be exploitable via Attacker must be have access to an admin account on the target site. This vulnerability appears to have been fixed in 2.8.Show less
1Pivotal Software
2Cloud Foundry Uaa
Cloud Foundry Uaa Release
Nov 21, 2024
Jun 25, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form pa...Show more
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.Show less
2Debian
Sensiolabs
2Debian Linux
Symfony
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security....Show more
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.Show less
2Debian
Sensiolabs
2Debian Linux
Symfony
Nov 21, 2024
Jun 13, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of t...Show more
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.Show less
1Mozilla
1Firefox
Nov 21, 2024
Jun 11, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious...Show more
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.Show less
1Mozilla
1Firefox
Nov 21, 2024
Jun 11, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from mal...Show more
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50. This vulnerability affects Firefox < 50.0.1.Show less
1St Project
1St
Nov 21, 2024
Jun 7, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would...Show more
st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").Show less
1Ibm
1Connections
Nov 21, 2024
Jun 4, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit th...Show more
IBM Connections 5.0, 5.5, and 6.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 135521.Show less
1Hekto Project
1Hekto
Nov 21, 2024
Jun 1, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
1Citrix
1Xenmobile Server
Nov 21, 2024
May 23, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.