Open redirect on https://werkenbijdefensie.nl/

Disclosed: 2017-07-27 08:14:12 By kuton To radancy
Medium
Vulnerability Details
**Domain and URL:** https://werkenbijdefensie.nl/ajax/contrast.php?contrast=1 **Description:** By adding "?contrast=1" after every url, it wil be redirect to the path after https://werkenbijdefensie.nl/ So I can redirect it to another website by adding one more slash ████████ ## Browsers Verified In: Any browser ## Steps To Reproduce: https://werkenbijdefensie.nl//codechoi.com/POC/Maximum/i.php?contrast=1 By visit this link you will be redirected to fake login.
Actions
View on HackerOne
Report Stats
  • Report ID: 242314
  • State: Closed
  • Substate: resolved
  • Upvotes: 12
Share this report