Open redirect via redirect_to parameter in tumblr.com

Disclosed: 2024-11-05 07:16:14 By shivangmauryaa To automattic
Low
Vulnerability Details
## Summary: URL redirection is sometimes used as a part of phishing attacks that confuse visitors about which web site they are visiting. ## Platform(s) Affected: Website ## Steps To Reproduce: 1. open any browser 2. enter https://www.tumblr.com/logout?redirect_to=https://evil.com%5C%40www.tumblr.com ## Supporting Material/References: video attached ## Impact A remote attacker can redirect users from your website to a specified URL. This problem may assist an attacker to conduct phishing attacks, trojan distribution, spammers.
Actions
View on HackerOne
Report Stats
  • Report ID: 2812583
  • State: Closed
  • Substate: resolved
  • Upvotes: 28
Share this report