Show filters
276 Total Results
Displaying 41-50 of 276
Sort by:
Attacker Value
Unknown
CVE-2021-44528
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
A open redirect vulnerability exists in Action Pack >= 6.0.0 that could allow an attacker to craft a "X-Forwarded-Host" headers in combination with certain "allowed host" formats can cause the Host Authorization middleware in Action Pack to redirect users to a malicious website.
0
Attacker Value
Unknown
CVE-2022-21651
Disclosure Date: January 05, 2022 (last updated February 23, 2025)
Shopware is an open source e-commerce software platform. An open redirect vulnerability has been discovered. Users may be arbitrary redirected due to incomplete URL handling in the shopware router. This issue has been resolved in version 5.7.7. There is no workaround and users are advised to upgrade as soon as possible.
0
Attacker Value
Unknown
CVE-2021-20875
Disclosure Date: December 24, 2021 (last updated February 23, 2025)
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks by having a user to access a specially crafted URL.
0
Attacker Value
Unknown
CVE-2021-40852
Disclosure Date: December 17, 2021 (last updated February 23, 2025)
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.
0
Attacker Value
Unknown
CVE-2021-43812
Disclosure Date: December 16, 2021 (last updated February 23, 2025)
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 do not filter out certain returnTo parameter values from the login url, which expose the application to an open redirect vulnerability. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2020-18985
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
0
Attacker Value
Unknown
CVE-2021-3829
Disclosure Date: December 10, 2021 (last updated February 23, 2025)
openwhyd is vulnerable to URL Redirection to Untrusted Site
0
Attacker Value
Unknown
CVE-2021-43532
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affects Firefox < 94.
0
Attacker Value
Unknown
CVE-2021-43064
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.
0
Attacker Value
Unknown
CVE-2021-36191
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers
0