Total
966 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-6927 | 1 Redhat | 2 Keycloak, Single Sign-on | 2024-02-14 | N/A | 6.1 MEDIUM |
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134. | |||||
CVE-2024-24808 | 1 Pyload | 1 Pyload | 2024-02-13 | N/A | 6.1 MEDIUM |
pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting users after login. pyLoad is validating URLs via the `get_redirect_url` function when redirecting users at login. This vulnerability has been patched with commit fe94451. | |||||
CVE-2024-24291 | 1 Yzmcms | 1 Yzmcms | 2024-02-13 | N/A | 6.1 MEDIUM |
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL. | |||||
CVE-2008-2052 | 1 Bitrix24 | 1 Bitrix Site Manager | 2024-02-09 | 4.3 MEDIUM | 6.1 MEDIUM |
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter. | |||||
CVE-2008-2951 | 2 Edgewall, Fedoraproject | 2 Trac, Fedora | 2024-02-09 | 5.8 MEDIUM | 6.1 MEDIUM |
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function. | |||||
CVE-2005-4206 | 1 Blackboard | 1 Academic Suite | 2024-02-09 | 4.0 MEDIUM | 6.1 MEDIUM |
Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a valid page. | |||||
CVE-2021-44528 | 1 Rubyonrails | 1 Rails | 2024-02-08 | 5.8 MEDIUM | 6.1 MEDIUM |
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website. | |||||
CVE-2024-21794 | 1 Rapidscada | 1 Rapid Scada | 2024-02-07 | N/A | 5.4 MEDIUM |
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page. | |||||
CVE-2023-36085 | 1 Sisqualwfm | 1 Sisqualwfm | 2024-02-05 | N/A | 6.1 MEDIUM |
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. This can lead to phishing attacks, malware distribution, and unauthorized access to sensitive resources. | |||||
CVE-2022-23527 | 2 Debian, Openidc | 2 Debian Linux, Mod Auth Openidc | 2024-02-05 | N/A | 6.1 MEDIUM |
mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server. Versions prior to 2.4.12.2 are vulnerable to Open Redirect. When providing a logout parameter to the redirect URI, the existing code in oidc_validate_redirect_url() does not properly check for URLs that start with /\t, leading to an open redirect. This issue has been patched in version 2.4.12.2. Users unable to upgrade can mitigate the issue by configuring mod_auth_openidc to only allow redirection when the destination matches a given regular expression with OIDCRedirectURLsAllowed. | |||||
CVE-2022-41275 | 1 Sap | 1 Solution Manager | 2024-02-05 | N/A | 6.1 MEDIUM |
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing attack, with little impact on confidentiality and integrity. | |||||
CVE-2023-49394 | 1 Easycorp | 1 Zentao | 2024-02-05 | N/A | 6.1 MEDIUM |
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly. | |||||
CVE-2024-0854 | 1 Synology | 1 Diskstation Manager | 2024-02-05 | N/A | 5.4 MEDIUM |
URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 allows remote authenticated users to conduct phishing attacks via unspecified vectors. | |||||
CVE-2023-48815 | 1 Keking | 1 Kkfileview | 2024-02-05 | N/A | 6.1 MEDIUM |
kkFileView v4.3.0 is vulnerable to Incorrect Access Control. | |||||
CVE-2023-48003 | 1 Aspnetzero | 1 Asp.net Zero | 2024-02-05 | N/A | 6.1 MEDIUM |
An open redirect through HTML injection in user messages in Asp.Net Zero before 12.3.0 allows remote attackers to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' in the WebSocket messages. | |||||
CVE-2023-51517 | 1 Codepeople | 1 Calculated Fields Form | 2024-02-05 | N/A | 5.4 MEDIUM |
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28. | |||||
CVE-2023-47548 | 1 Softlabbd | 1 Integrate Google Drive | 2024-02-05 | N/A | 6.1 MEDIUM |
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site: from n/a through 1.3.2. | |||||
CVE-2023-48928 | 1 Franklin-electric | 1 System Sentinel Anyware | 2024-02-05 | N/A | 6.1 MEDIUM |
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | |||||
CVE-2023-32101 | 1 Pexlechris | 1 Library Viewer | 2024-02-05 | N/A | 6.1 MEDIUM |
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pexle Chris Library Viewer.This issue affects Library Viewer: from n/a through 2.0.6. | |||||
CVE-2023-47168 | 1 Mattermost | 1 Mattermost | 2024-02-05 | N/A | 6.1 MEDIUM |
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to= |