Open redirect in Signing in via Social Sites

Disclosed: 2017-05-17 14:09:01 By rajauzairabdullah To weblate
Medium
Vulnerability Details
Weak **Authentication** Leads to the **Open redirection** to **_Malicios Sites_** : ### Signing in via Facebook : + https://hosted.weblate.org/accounts/login/facebook/?next=///evil.com ### Signing in via Gmail : + https://hosted.weblate.org/accounts/login/google-oauth2/?next=///evil.com ### Signing in via Github: + https://hosted.weblate.org/accounts/login/github/?next=///evil.com ### Signing in via Bitbucket: + https://hosted.weblate.org/accounts/login/bitbucket/?next=///evil.com ### Signing in via Gitlab: + https://hosted.weblate.org/accounts/login/gitlab/?next=///evil.com ### Vulnarable Parameter: **" next "** Greets **Raja Uzair Abdullah**
Actions
View on HackerOne
Report Stats
  • Report ID: 223718
  • State: Closed
  • Substate: duplicate
  • Upvotes: 3
Share this report