← Back
CWE-601

1,578 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,578)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zzzcms
1Zzzphp
Jun 17, 2026
Oct 18, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
1Python
1Urllib3
Nov 21, 2024
Oct 15, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization hea...Show more
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).Show less
1Mosparo
1Mosparo
Jun 17, 2026
Oct 4, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Open Redirect in GitHub repository mosparo/mosparo prior to 1.0.2.
1Gitlab
1Gitlab
Jun 17, 2026
Sep 29, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some...Show more
An issue has been discovered in GitLab affecting all versions starting from 8.15 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible to hijack some links and buttons on the GitLab UI to a malicious page.Show less
1Symantec
1Identity Portal
Jun 17, 2026
Sep 19, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An authenticated user can see and modify the value for ‘next’ query parameter in Symantec Identity Portal 14.4
1Phpipam
1Phpipam
Jun 17, 2026
Sep 14, 2023
N/A· v4
4.8 MEDIUM· v3
3.3 LOW· v2
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads...Show more
A vulnerability was found in phpipam 1.5.1. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Header Handler. The manipulation of the argument X-Forwarded-Host leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239732.Show less
1Icewarp
1Deep Castle G2
Jun 17, 2026
Sep 14, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
1Couchcms
1Couchcms
Jun 17, 2026
Sep 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
1Sap
1S/4hana
Jun 17, 2026
Sep 8, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiali...Show more
SAP S/4HANA Manage Catalog Items and Cross-Catalog searches Fiori apps allow an attacker to redirect users to a malicious site due to insufficient URL validation. As a result, it may have a slight impact on confidentiality and integrity.Show less
1Cisco
1Hyperflex Hx Data Platform
Jun 17, 2026
Sep 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to impr...Show more
A vulnerability in the web-based management interface of Cisco HyperFlex HX Data Platform could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.Show less
2Cacti
Fedoraproject
2Cacti
Fedora
Jun 17, 2026
Sep 5, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arbitrary website after a change password performed via a specifically cra...Show more
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arbitrary website after a change password performed via a specifically crafted URL. The `auth_changepassword.php` file accepts `ref` as a URL parameter and reflects it in the form used to perform the change password. It's value is used to perform a redirect via `header` PHP function. A user can be tricked in performing the change password operation, e.g., via a phishing message, and then interacting with the malicious website where the redirection has been performed, e.g., downloading malwares, providing credentials, etc. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1I Pro
1Video Insight
Jun 17, 2026
Sep 5, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
1Startrinity
1Softswitch
Jun 17, 2026
Sep 3, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
StarTrinity Softswitch version 2023-02-16 - Open Redirect (CWE-601)
1Gitlab
1Gitlab
Jun 17, 2026
Sep 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create...Show more
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.Show less
1Jupyter
1Jupyter Server
Jun 17, 2026
Aug 28, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirecte...Show more
jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can cause successful login or an already logged-in session to be redirected to arbitrary sites, which should be restricted to Jupyter Server-served URLs. This issue has been addressed in commit `29036259` which is included in release 2.7.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
2Apache
Debian
2Debian Linux
Tomcat
Jun 17, 2026
Aug 25, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0...Show more
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default) web application.Show less
1Openstack
1Horizon
Jun 17, 2026
Aug 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
1Southrivertech
1Titan Ftp Server
Jun 17, 2026
Aug 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
1Arscode
1Ninja Popups
Jun 17, 2026
Aug 10, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Unauth. Open Redirect vulnerability in Arscode Ninja Popups plugin <= 4.7.5 versions.
1Opnsense
1Opnsense
Jun 17, 2026
Aug 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An open redirect in the Login page of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.