Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open Redirect On Login Page. #6906

Open
ghost opened this issue Jan 9, 2020 · 0 comments
Open

Open Redirect On Login Page. #6906

ghost opened this issue Jan 9, 2020 · 0 comments

Comments

@ghost
Copy link

ghost commented Jan 9, 2020

Hello, I was doing a bug bounty for a company and stumbled upon an open redirect on the login page ~

Steps to reproduce:

Results (Expected/Actual):

User should be notified that they are leaving domain or shouldn't be redirected at-all. / Instead user gets redirected without any confirmation or notice.
Portswigger refrence on open redirect: https://portswigger.net/kb/issues/00500100_open-redirection-reflected

Environment

Version: 2.8.2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

0 participants