← Back
CWE-601

1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,576)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cloudera
1Hue
Nov 21, 2024
May 22, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
1Ilias
1Ilias
Nov 21, 2024
May 17, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
ILIAS 5.1.x, 5.2.x, and 5.3.x before 5.3.5 redirects a logged-in user to a third-party site via the return_to_url parameter.
1Mybb
1Mybb
Nov 21, 2024
May 13, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
MyBB 1.8.15, when accessed with Microsoft Edge, mishandles 'target="_blank" rel="noopener"' in A elements, which makes it easier for remote attackers to conduct redirection attacks.
1Impinj
1R420 Rfid Reader Firmware
Nov 21, 2024
May 11, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe,...Show more
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party application or perform other malicious actions.Show less
1Jenkins
1Google Login
Nov 21, 2024
May 8, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
1Rsa
1Authentication Manager
Nov 21, 2024
May 8, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially po...Show more
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains.Show less
1Blackboard
1Blackboard Learn
Nov 21, 2024
Apr 30, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibbolet...Show more
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.Show less
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
2Debian
Wordpress
2Debian Linux
Wordpress
Nov 21, 2024
Apr 16, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where Special:Search allows redirects to any interwiki link.
2Debian
Mediawiki
2Debian Linux
Mediawiki
Nov 21, 2024
Apr 13, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
1Wolfcms
1Wolf Cms
Jun 17, 2026
Apr 4, 2018
N/A· v4
4.8 MEDIUM· v3
4.9 MEDIUM· v2
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL.
2Apple
Canonical
7Icloud
Iphone OsItunes+4 more
Nov 21, 2024
Apr 3, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is...Show more
An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to spoof user-interface information (about whether the entire content is derived from a valid TLS session) via a crafted web site that sends a 401 Unauthorized redirect.Show less
1Elastic
1Kibana
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link t...Show more
The fix in Kibana for ESA-2017-23 was incomplete. With X-Pack security enabled, Kibana versions before 6.1.3 and 5.6.7 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary website.Show less
1Netiq
1Identity Manager
Jun 17, 2026
Mar 28, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The NetIQ Identity Manager user console, in versions prior to 4.7, is susceptible to URL redirection.
1Open Audit
1Open Audit
Jun 17, 2026
Mar 26, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be...Show more
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code.Show less
1Microsoft
1Exchange Server
Nov 21, 2024
Mar 14, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Mic...Show more
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941.Show less
1Emc
1Rsa Archer
Nov 21, 2024
Mar 8, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the...Show more
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the intent of obtaining sensitive information from the users.Show less
1Soconnect
1Sowifi Hotspot Firmware
Jun 17, 2026
Mar 7, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL.
1Netiq
1Access Manager
Nov 21, 2024
Mar 2, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Novell Access Manager Admin Console and IDP servers before 4.3.3 have a URL that could be used by remote attackers to trigger unvalidated redirects to third party sites.