Open redirect while disconnecting Email
W
Weblate
Submitted None
Actions:
Reported by
atruba
Vulnerability Details
Technical details and impact analysis
Hi team,
there is a open redirect end point when any account owner disconnect email accounts. He is redirected to some other domain.
Vulnerable URL
https://demo.weblate.org/accounts/disconnect/email/2354/?next=http://google.com
POC
Steps:
Go to authentication tab.
Disconnect Email account and capture the request.
Now, after next= write https://evil.com.
You are redirected to evil.com
Thanks,
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Open Redirect