Vulnerabilities > URL Redirection to Untrusted Site ('Open Redirect')

DATE CVE VULNERABILITY TITLE RISK
2020-04-14 CVE-2020-6215 Open Redirect vulnerability in SAP Netweaver AS Abap Business Server Pages
SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
network
low complexity
sap CWE-601
6.1
2020-04-14 CVE-2020-6211 Open Redirect vulnerability in SAP Businessobjects Business Intelligence Platform 4.1/4.2
SAP Business Objects Business Intelligence Platform (AdminTools), versions 4.1, 4.2, allows an attacker to redirect users to a malicious site due to insufficient URL validation and steal credentials of the victim, leading to URL Redirection vulnerability.
network
low complexity
sap CWE-601
6.1
2020-04-14 CVE-2020-6223 Open Redirect vulnerability in SAP Businessobjects Business Intelligence Platform 4.1/4.2
The open document of SAP Business Objects Business Intelligence Platform, versions 4.1, 4.2, allows an attacker to modify certain error pages to include malicious content.
network
low complexity
sap CWE-601
6.1
2020-04-13 CVE-2020-8430 Open Redirect vulnerability in Stormshield Network Security
Stormshield Network Security 310 3.7.10 devices have an auth/lang.html?rurl= Open Redirect vulnerability on the captive portal.
network
low complexity
stormshield CWE-601
6.1
2020-04-07 CVE-2020-11611 Open Redirect vulnerability in Cross Domain Local Storage Project Cross Domain Local Storage
An issue was discovered in xdLocalStorage through 2.0.5.
6.1
2020-04-07 CVE-2020-11515 Open Redirect vulnerability in Rankmath SEO
The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to create new URIs (that redirect to an external web site) via the unsecured rankmath/v1/updateRedirection REST API endpoint.
network
low complexity
rankmath CWE-601
6.1
2020-04-04 CVE-2020-11529 Open Redirect vulnerability in Getgrav Grav
Common/Grav.php in Grav before 1.7 has an Open Redirect.
network
low complexity
getgrav CWE-601
6.1
2020-04-03 CVE-2020-8143 Open Redirect vulnerability in Revive-Adserver Revive Adserver
An Open Redirect vulnerability was discovered in Revive Adserver version < 5.0.5 and reported by HackerOne user hoangn144.
network
low complexity
revive-adserver CWE-601
6.1
2020-04-02 CVE-2020-1927 Open Redirect vulnerability in multiple products
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
6.1
2020-03-20 CVE-2019-19484 Open Redirect vulnerability in Centreon
Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.
network
low complexity
centreon CWE-601
6.1