https://xmpp.nextcloud.com///;@www.google.com allows open redirect

Disclosed: 2017-08-13 13:32:34 By todayisnew To nextcloud
Unknown
Vulnerability Details
Good day :) Hope it goes well, an open redirect exists on the main xmpp.nextcloud.com domain allowing "bad hackers" to do bad things :) Poc https://xmpp.nextcloud.com///;@www.google.com May you be well on your side of the screen :) -Eric
Actions
View on HackerOne
Report Stats
  • Report ID: 211213
  • State: Closed
  • Substate: resolved
  • Upvotes: 17
Share this report