← Back
CWE-601

1,578 CVEs • Abstraction: Base • Likelihood of Exploit: Low

URL Redirection to Untrusted Site ('Open Redirect')

A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.

JSON object

Loading...

CVEs (1,578)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lambdaisland
1Uri
Jun 17, 2026
Mar 27, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious URLs to be parsed by the `lambdaisland/uri` and return the wrong authorit...Show more
lambdaisland/uri is a pure Clojure/ClojureScript URI library. In versions prior to 1.14.120 `authority-regex` allows an attacker to send malicious URLs to be parsed by the `lambdaisland/uri` and return the wrong authority. This issue is similar to but distinct from CVE-2020-8910. The regex in question doesn't handle the backslash (`\`) character in the username correctly, leading to a wrong output. ex. a payload of `https://example.com\\@google.com` would return that the host is `google.com`, but the correct host should be `example.com`. Given that the library returns the wrong authority this may be abused to bypass host restrictions depending on how the library is used in an application. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Twofactorauth Project
1Twofactorauth
Nov 21, 2024
Mar 25, 2023
N/A· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manipulation of the argument from leads to open redirect. It is possible to...Show more
A vulnerability classified as problematic has been found in Arno0x TwoFactorAuth. This affects an unknown part of the file login/login.php. The manipulation of the argument from leads to open redirect. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The patch is named 8549ad3cf197095f783643e41333586d6a4d0e54. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-223803.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Adobe
2Experience Manager
Experience Manager Cloud Service
Jun 17, 2026
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect...Show more
Experience Manager versions 6.5.15.0 (and earlier) are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.Show less
1Hpe
2Flexfabric 5700 40xg 2qsfp+ Firmware
Flexfabric 5700 48g 4xg 2qsfp+ Firmware
Jun 17, 2026
Mar 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the fol...Show more
Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE FlexFabric 5700 Switch Series version R2432P61 or later. Show less
1Rapid7
1Insightvm
Jun 17, 2026
Mar 20, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data...Show more
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179.  Show less
1Microsoft
1Edge Chromium
Jun 17, 2026
Mar 14, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
1Microsoft
2Sharepoint Foundation
Sharepoint Server
Jun 17, 2026
Mar 14, 2023
N/A· v4
3.1 LOW· v3
N/A· v2
Microsoft SharePoint Server Spoofing Vulnerability
1Gitlab
1Gitlab
Jun 17, 2026
Mar 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
1Gitlab
1Dynamic Application Security Testing Analyzer
Jun 17, 2026
Mar 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
1Sigb
1Pmb
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external domain via a crafted URL.