Loading HuntDB...

Open redirect while disconnecting Email

W
Weblate
Submitted None
Reported by atruba

Vulnerability Details

Technical details and impact analysis

Open Redirect
Hi team, there is a open redirect end point when any account owner disconnect email accounts. He is redirected to some other domain. Vulnerable URL https://demo.weblate.org/accounts/disconnect/email/2354/?next=http://google.com POC Steps: Go to authentication tab. Disconnect Email account and capture the request. Now, after next= write https://evil.com. You are redirected to evil.com Thanks,

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Open Redirect