FirstBlood-#1079 — Open redirect still works on logout.php
This issue was discovered on FirstBlood v3
On 2022-12-08, ayush1098 Level 8 reported:
Hello Team,
Summary:
The open redirect is still working on logout.php
endpoint. We can redirect the user to any website.
Steps To Reproduce:
Go to this --> https://ffa62eb87170-ayush1098.a.firstbloodhackers.com/drpanel/logout.php?ref=/%09/evil.com
It will redirect the user to evil.com
Impact:
Phising
Thanks & Regards
Ayush Singh
P4 Low
Endpoint: logout.php
Parameter: ref
Payload: /%09/evil.com
FirstBlood ID: 68
Vulnerability Type: Open Redirect
The open redirect on /drpanel/logout.php remains unfixed
Creator & Administrator
Congratulations, you were the third user to report this!