Ports are not shown in third-party site redirect warning page.
Low
S
Semrush
Submitted None
Actions:
Reported by
b3f53dc9b2061f7df0c2ffd
Vulnerability Details
Technical details and impact analysis
**Summary:**
[Ports are not shown in third-party site redirect warning page]
Vulnerable Endpoint :- https://www.semrush.com/redirect?urlhttp://example.com:1337
**Description:** I noticed #311330 this report where you guys fixed a open redirect report by adding a external third-party site redirect warning page . It was a great fix . Although a issue caught in my eye . Urls contains a protocol and Ports . If I add a url with any other ports like 1337 then it's not shown in the external warning page what can be used to take a user to any other place then user expected to go .
Browsers Verified In: Chrome and Mozilla Firefox
## Steps To Reproduce:
Visit https://www.semrush.com/redirect?url=http://example.com:1337
You will see a warning page only saying about the domain but no warning about the ports like screenshot added below
But the source says it will take user to http://example.com:1337 not only example.com
<a href="http://example.com:1337" id="js-site-link" class="site_link" data-test-site-link="">
Go to site </a>
FIX :-
I can suggest possible fix here :-
Show the Ports of the inputted url in the Warning page .
Thanks
## Impact
I noticed in url= parameter many protocols can be used . Like I can use any port and on my android if I visit https://www.semrush.com/redirect?url=http://example.com:1337 and click on Go to site then it will open my virtual environment's.
Report Details
Additional information and metadata
State
Closed
Substate
Duplicate