Open Redirection
Low
J
JetBlue
Submitted None
Actions:
Reported by
doosec101
Vulnerability Details
Technical details and impact analysis
## Summary:
Hi jetblue Security Team.
The following URL is vulnerable to an open redirect (it will redirect to google.com):
- https://█████[email protected]
Work at Google Chrome & Other Browser
Except Firefox will ask you first if you want to redirect to that page , See:-
█████████
##What is Open Redirect:-
Open redirection vulnerabilities arise when an application incorporates user-controllable data into the target of a redirection in an unsafe way. An attacker can construct a URL within the application that causes a redirection to an arbitrary external domain. This behavior can be leveraged to facilitate phishing attacks against users of the application. The ability to use an authentic application URL
Supporting Material/References:
-https://blog.detectify.com/2019/05/16/the-real-impact-of-an-open-redirect/
-https://medium.com/@0xrishabh/open-redirect-to-account-takeover-e939006a9f24
## Steps To Reproduce:
1. Go to https://████[email protected]
2. Redirect to google.com
## Impact
Open Redirection
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Open Redirect