Loading HuntDB...

Unvalidated redirect on user profile website

Z
Zomato
Submitted None
Reported by roshanpty

Vulnerability Details

Technical details and impact analysis

Open Redirect
The user profile redirect request is not properly validated. The presence of parameter t which is being passed through the request is verified but same value can be reused to any unauthenticated or authenticated user to redirect them to any web site. Sample link is given below. https://www.zomato.com/redirect?u=http%3A%2F%2Ftest.com&t=38dc43d5f007f4c5d974f6c74f065158&g=user-profile-website

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Open Redirect