Open redirect by the parameter redirectUri in the URL
Low
B
BlackRock
Submitted None
Actions:
Reported by
marciosz_
Vulnerability Details
Technical details and impact analysis
The following URL is vulnerable to an open redirect (it will redirect to google.com)
https://www.blackrock.com/authplatform/user/activate-success?redirectUri=https://google.com
After clicking on "return to site" it will be redirected to the page
Steps To Reproduce:
Enter on this link https://www.blackrock.com/authplatform/user/activate-success?redirectUri=https://google.com
Redirected to https://google.com
## Impact
Phishing attacks to redirect users to malicious sites without realizing it
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Open Redirect