Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2020-02-28 CVE-2020-6803 Open Redirect vulnerability in Mozilla Webthings Gateway
An open redirect is present on the gateway's login page, which could cause a user to be redirected to a malicious site after logging in.
network
low complexity
mozilla CWE-601
6.1
2020-02-24 CVE-2019-4595 Open Redirect vulnerability in IBM Sterling B2B Integrator
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2020-02-20 CVE-2019-20479 Open Redirect vulnerability in multiple products
A flaw was found in mod_auth_openidc before version 2.4.1.
network
low complexity
openidc debian fedoraproject opensuse CWE-601
6.1
2020-02-19 CVE-2014-9617 Open Redirect vulnerability in Netsweeper
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
network
low complexity
netsweeper CWE-601
6.1
2020-02-14 CVE-2019-19758 Open Redirect vulnerability in Lenovo products
A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated, remote attacker to redirect a user to an untrusted web page.
network
low complexity
lenovo CWE-601
6.1
2020-02-03 CVE-2013-2621 Open Redirect vulnerability in Telaen Project Telaen
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
network
low complexity
telaen-project CWE-601
6.1
2020-01-30 CVE-2020-5233 Open Redirect vulnerability in Oauth2 Proxy Project Oauth2 Proxy
OAuth2 Proxy before 5.0 has an open redirect vulnerability.
network
low complexity
oauth2-proxy-project CWE-601
6.1
2020-01-28 CVE-2013-2764 Open Redirect vulnerability in United-Security-Providers Secure Entry Server
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
network
low complexity
united-security-providers CWE-601
6.1
2020-01-28 CVE-2019-4631 Open Redirect vulnerability in IBM Security Secret Server 10.6/10.7
IBM Security Secret Server 10.7 could allow a remote attacker to conduct phishing attacks, using an open redirect attack.
network
low complexity
ibm CWE-601
6.1
2020-01-23 CVE-2020-7936 Open Redirect vulnerability in Plone
An open redirect on the login form (and possibly other places) in Plone 4.0 through 5.2.1 allows an attacker to craft a link to a Plone Site that, when followed, and possibly after login, will redirect to an attacker's site.
network
low complexity
plone CWE-601
6.1