Open redirect by the parameter redirectUri in the URL

Disclosed: 2022-04-21 22:10:00 By marciosz_ To blackrock
Low
Vulnerability Details
The following URL is vulnerable to an open redirect (it will redirect to google.com) https://www.blackrock.com/authplatform/user/activate-success?redirectUri=https://google.com After clicking on "return to site" it will be redirected to the page Steps To Reproduce: Enter on this link https://www.blackrock.com/authplatform/user/activate-success?redirectUri=https://google.com Redirected to https://google.com ## Impact Phishing attacks to redirect users to malicious sites without realizing it
Actions
View on HackerOne
Report Stats
  • Report ID: 1250758
  • State: Closed
  • Substate: resolved
  • Upvotes: 15
Share this report