Loading HuntDB...

Open Redirect via Non-Latin Subdomain in vcc-*.8x8.com/AGUI/█.php

Low
8
8x8 Bounty
Submitted None

Team Summary

Official summary from 8x8 Bounty

@pentestor reported an issue where a filter that prevents the usage of [1-9] and [a-z] characters in the `subdomain` parameter can be bypassed by utilizing a non-Latin domain. The report demonstrates the exploitation of this vulnerability by redirecting to the `नमस्ते.भारत` domain. The issue has been addressed.

Reported by pentestor

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$100.00

Submitted

Weakness

Open Redirect