CWE-601
1,576 CVEs • Abstraction: Base • Likelihood of Exploit: Low
URL Redirection to Untrusted Site ('Open Redirect')
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
CVEs (1,576)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Broadcom 1Symantec Siteminder Nov 20, 2024 Mar 28, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argu...Show more |
An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab integration with Jira that a could cause the web application to redirect the request to the attacke...Show more |
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below...Show more |
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. |
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter. |
The Page Builder KingComposer WordPress plugin through 2.9.6 does not validate the id parameter before redirecting the user to it via the kc_get_thumbn AJAX action available to both unauthenticated and authenticated user...Show more |
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions a...Show more |
alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how All...Show more |
Nextcloud talk is a self hosting messaging service. In versions prior 12.1.2 an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. Thi...Show more |
Open Redirect in GitHub repository archivy/archivy prior to 1.7.0. |
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. |
Multiple Open Redirect in GitHub repository nitely/spirit prior to 0.12.3. |
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. |
2Openstack Redhat2Nova Openstack PlatformJun 17, 2026 Mar 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL. |
1Cherwell 1Cherwell Service Management Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. It accepts and reflects arbitrary domains supplied via a client-controlled Host header. Injection of a malicious URL in the Host...Show more |
1Cherwell 1Cherwell Service Management Jun 17, 2026 Feb 28, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in the web application in Cherwell Service Management (CSM) 10.2.3. Injection of a malicious payload within the RelayState= parameter of the HTTP request body results in the hijacking of the form...Show more |
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter. |
In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. |
1Hpe 1Oneview Global Dashboard Jun 17, 2026 Feb 24, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has provided a software update to resolve this vulnerability in HPE OneView Global Dashboard. |
Open Redirect on Rudloff/alltube in Packagist rudloff/alltube prior to 3.0.1. |