Vulnerabilities (CVE)

Filtered by CWE-601
Total 966 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18178 1 Progress 1 Sitefinity 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the redirection target, if the target is specified using a certain %40 syntax. This is fixed in 10.1.
CVE-2018-8813 1 Wolfcms 1 Wolf Cms 2024-02-04 4.9 MEDIUM 4.8 MEDIUM
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL.
CVE-2018-6324 1 F-secure 1 Radar 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
CVE-2018-7473 1 Soconnect 2 Sowifi Hotspot, Sowifi Hotspot Firmware 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL.
CVE-2018-5304 1 Impinj 2 R420 Rfid Reader, R420 Rfid Reader Firmware 2024-02-04 4.3 MEDIUM 4.3 MEDIUM
An issue was discovered on the Impinj Speedway Connect R420 RFID Reader before 2.2.2. The affected web interface is vulnerable to ClickJacking or UI Redressing: it is possible to access the web application in an iframe, and clicking on the iframe will redirect to a third-party application or perform other malicious actions.
CVE-2018-6200 1 Vbulletin 1 Vbulletin 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.
CVE-2018-8937 1 Open-audit 1 Open-audit 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
An issue was discovered in Open-AudIT Professional 2.1. It is possible to inject a malicious payload in the redirect_url parameter to the /login URI to trigger an open redirect. A "data:text/html;base64," payload can be used with JavaScript code.
CVE-2017-8945 1 Hp 1 Icewall Federation Agent 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.
CVE-2017-0363 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 has a flaw where Special:UserLogin?returnto=interwiki:foo will redirect to external sites.
CVE-2017-16652 2 Debian, Sensiolabs 2 Debian Linux, Symfony 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
CVE-2018-1248 1 Rsa 1 Authentication Manager 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
RSA Authentication Manager Security Console, Operation Console and Self-Service Console, version 8.3 and earlier, is affected by a Host header injection vulnerability. This could allow a remote attacker to potentially poison HTTP cache and subsequently redirect users to arbitrary web domains.
CVE-2018-6520 1 Simplesamlphp 1 Simplesamlphp 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
SimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open redirect protection mechanism via crafted authority data in a URL.
CVE-2015-3898 1 Bonitasoft 1 Bonita Bpm Portal 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/loginservice.
CVE-2018-11408 2 Debian, Sensiolabs 2 Debian Linux, Symfony 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.
CVE-2018-3743 1 Hekto Project 1 Hekto 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Open redirect in hekto <=0.2.3 when target domain name is used as html filename on server.
CVE-2017-6932 2 Debian, Drupal 2 Debian Linux, Drupal 2024-02-04 5.8 MEDIUM 4.7 MEDIUM
Drupal core 7.x versions before 7.57 has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
CVE-2015-8094 1 Cloudera 1 Hue 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
CVE-2018-0924 1 Microsoft 1 Exchange Server 2024-02-04 4.3 MEDIUM 6.5 MEDIUM
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941.
CVE-2018-1220 1 Emc 1 Rsa Archer 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
EMC RSA Archer, versions prior to 6.2.0.8, contains a redirect vulnerability in the QuickLinks feature. A remote attacker may potentially exploit this vulnerability to redirect genuine users to phishing websites with the intent of obtaining sensitive information from the users.
CVE-2018-11041 1 Pivotal Software 2 Cloud Foundry Uaa, Cloud Foundry Uaa-release 2024-02-04 5.8 MEDIUM 6.1 MEDIUM
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.