Loading HuntDB...

Open redirect while disconnecting authenticated account

Medium
W
Weblate
Submitted None
Reported by gsecure

Vulnerability Details

Technical details and impact analysis

Open Redirect
Hi team, there is a open redirect end point when any account owner disconnect authenticated accounts say google. He is redirected to some other domain. Vulnerable URL --- [demo.weblate.org/accounts/disconnect/google-oauth2/2335/?next=](demo.weblate.org/accounts/disconnect/google-oauth2/2335/?next=) POC 1. Go to authentication tab. 2. Disconnect Google account and capture the request. 3. Now, after next= write https://evil.com. 4. You are redirected to evil.com video POC is attached. Best Regards Gurwinder

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Open Redirect