An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 bef
Lack of "current" GET parameter validation during the action of changing a language leads to an open redirect vulnerabil
Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
The T1 WordPress theme through 19.0 is vulnerable to unauthenticated open redirect with which any attacker and redirect
Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote
The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it poss
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the pag
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a c
Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers t
Glewlwyd SSO server 2.x through 2.7.6 allows open redirection via redirect_uri.
The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to i
An Open Redirect vulnerability was found in osTicky2 below 2.2.8. osTicky (osTicket Bridge) by SmartCalc is a Joomla 3.x
DOM-based HTML injection vulnerability in the main page of Darktrace Threat Visualizer version 6.1.27 (bundle version 61
Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101,
Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA thro
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 be
HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 be
The Travelpayouts: All Travel Brands in One Place WordPress plugin through 1.1.15 is vulnerable to Open Redirect due to
Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta
In JetBrains TeamCity before 2024.03 open redirect was possible on the login page
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported ve
The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is
Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument
Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirec
A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and be
Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, le
An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th
An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows a
The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contr
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Ma
The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and
An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' param
An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and chang
Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScale
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect W
WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the re
Inadequate validation of URLs could result into an invalid check whether an redirect URL is internal or not..
OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSea
There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.
An Open Redirect vulnerability in the page parameter of vTiger CRM v7.4.0 allows attackers to redirect users to a malici
If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of anot
Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulner
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerab
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Inte
Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a t
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if
Frequently Asked Questions
What is CWE-601?
CWE-601 (CWE-601) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-601?
There are 1,953 CVE records associated with CWE-601 in our database. Of these, 31 are critical severity, 165 are high severity, and 1323 are medium severity.
How can I protect against CWE-601 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-601 using AI-powered security agents.
Detect CWE-601 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-601 vulnerabilities across your infrastructure.
Get Started