Open redirect in semrush.com
Low
S
Semrush
Submitted None
Actions:
Reported by
batuhanu
Vulnerability Details
Technical details and impact analysis
**Summary:**
There is an open redirect on https://www.semrush.com/login/?redirect_to=.
By using /\ at the start of the link, you can bypass the open redirect filter.
**Description:**
An attacker can control the value of the "redirect_to" parameter and make it redirect to a malicious endpoint.
## Steps To Reproduce:
Visit: `www.semrush.com/login/?redirect_to=/\google.com`
Once you login, you will be redirected to google.com
## Impact
This vulnerability can be used for phishing attacks
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Open Redirect