Open redirect via redirect_to parameter in tumblr.com
Low
A
Automattic
Submitted None
Actions:
Reported by
shivangmauryaa
Vulnerability Details
Technical details and impact analysis
## Summary:
URL redirection is sometimes used as a part of phishing attacks that confuse visitors about which web site they are visiting.
## Platform(s) Affected:
Website
## Steps To Reproduce:
1. open any browser
2. enter https://www.tumblr.com/logout?redirect_to=https://evil.com%5C%40www.tumblr.com
## Supporting Material/References:
video attached
## Impact
A remote attacker can redirect users from your website to a specified URL. This problem may assist an attacker to conduct phishing attacks, trojan distribution, spammers.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Open Redirect