CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter. |
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter. |
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks. |
1Impinj 1R420 Rfid Reader Firmware Nov 21, 2024 May 11, 2018 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe,...Show more |
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login. |
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially po...Show more |
1Blackboard 1Blackboard Learn Nov 21, 2024 Apr 30, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibbolet...Show more |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Apr 16, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server. |
2Debian Wordpress2Debian Linux WordpressNov 21, 2024 Apr 16, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link. |
2Debian Mediawiki2Debian Linux MediawikiNov 21, 2024 Apr 13, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites. |
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL. |
2Apple Canonical7Icloud Iphone OsItunes+4 moreNov 21, 2024 Apr 3, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is...Show more |
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link t...Show more |
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection. |
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be...Show more |
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Mic...Show more |
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the...Show more |
1Soconnect 1Sowifi Hotspot Firmware Jun 17, 2026 Mar 7, 2018 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL. |
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites. |