Vulnerabilities (CVE)

Filtered by CWE-601
Total 1111 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-1279 1 Gitlab 1 Gitlab 2024-11-21 N/A 2.6 LOW
An issue has been discovered in GitLab affecting all versions starting from 4.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1 where it was possible to create a URL that would redirect to a different project.
CVE-2023-0748 1 Btcpayserver 1 Btcpayserver 2024-11-21 N/A 6.4 MEDIUM
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
CVE-2023-0681 1 Rapid7 1 Insightvm 2024-11-21 N/A 4.3 MEDIUM
Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ‘page’ parameter of the ‘data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179. 
CVE-2023-0155 1 Gitlab 1 Gitlab 2024-11-21 N/A 5.4 MEDIUM
An issue has been discovered in GitLab CE/EE affecting all versions before 15.8.5, 15.9.4, 15.10.1. Open redirects was possible due to framing arbitrary content on any page allowing user controlled markdown
CVE-2022-4720 1 Ikus-soft 1 Rdiffweb 2024-11-21 N/A 6.1 MEDIUM
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4644 1 Ikus-soft 1 Rdiffweb 2024-11-21 N/A 6.1 MEDIUM
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.4.
CVE-2022-4589 1 Django Terms And Conditions Project 1 Django Terms And Conditions 2024-11-21 N/A 5.5 MEDIUM
A vulnerability has been found in cyface Terms and Conditions Module up to 2.0.9 and classified as problematic. Affected by this vulnerability is the function returnTo of the file termsandconditions/views.py. The manipulation leads to open redirect. The attack can be launched remotely. Upgrading to version 2.0.10 is able to address this issue. The name of the patch is 03396a1c2e0af95e12a45c5faef7e47a4b513e1a. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216175.
CVE-2022-4317 1 Gitlab 1 Dynamic Application Security Testing Analyzer 2024-11-21 N/A 5.0 MEDIUM
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 1.47 before 3.0.51, which sends custom request headers in redirects.
CVE-2022-48358 1 Huawei 2 Emui, Harmonyos 2024-11-21 N/A 7.4 HIGH
The BatteryHealthActivity has a redirection vulnerability. Successful exploitation of this vulnerability by a malicious app can cause service exceptions.
CVE-2022-46784 1 Squaredup 1 Dashboard Server 2024-11-21 N/A 6.1 MEDIUM
SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5.1 GA.)
CVE-2022-46407 1 Ericsson 1 Network Manager 2024-11-21 N/A 4.8 MEDIUM
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability
CVE-2022-45582 1 Openstack 1 Horizon 2024-11-21 N/A 6.1 MEDIUM
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
CVE-2022-45169 1 Liveboxcloud 1 Vdesk 2024-11-21 N/A 5.4 MEDIUM
An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, allowing an authenticated user to send an arbitrary push notification to any other user of the system. This push notification can include an (invisible) clickable link.
CVE-2022-44488 1 Adobe 2 Experience Manager, Experience Manager Cloud Service 2024-11-21 N/A 3.5 LOW
Adobe Experience Manager version 6.5.14 (and earlier) is affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. A low-privilege authenticated attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
CVE-2022-44215 1 Southrivertech 1 Titan Ftp Server 2024-11-21 N/A 6.1 MEDIUM
There is an open redirect vulnerability in Titan FTP server 19.0 and below. Users are redirected to any target URL.
CVE-2022-43950 1 Fortinet 2 Fortinac, Fortinac-f 2024-11-21 N/A 4.3 MEDIUM
A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redirect users to any arbitrary website via a crafted URL.
CVE-2022-41965 1 Apereo 1 Opencast 2024-11-21 N/A 5.7 MEDIUM
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to Opencast 12.5, Opencast's Paella authentication page could be used to redirect to an arbitrary URL for authenticated users. The vulnerability allows attackers to redirect users to sites outside of one's Opencast install, potentially facilitating phishing attacks or other security issues. This issue is fixed in Opencast 12.5 and newer.
CVE-2022-41275 1 Sap 1 Solution Manager 2024-11-21 N/A 6.1 MEDIUM
In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link that, if clicked by a logged-in user, can be redirected to a malicious page that could read or modify sensitive information, or expose the user to a phishing attack, with little impact on confidentiality and integrity.
CVE-2022-41273 1 Sap 2 Contract Lifecycle Manager, Sourcing 2024-11-21 N/A 4.3 MEDIUM
Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be a legitimate SAP Sourcing URL, since the victim doesn’t suspect the threat, they click on the link, log in to SAP Sourcing and CLM and at this point, they get redirected to a malicious website.            
CVE-2022-41215 1 Sap 1 Netweaver Application Server Abap 2024-11-21 N/A 4.7 MEDIUM
SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due to insufficient URL validation. This could lead to the user being tricked to disclose personal information.