open redirected by host header

Disclosed: 2024-12-02 13:46:09 By black_world To localizejs
Unknown
Vulnerability Details
An Open Redirect vulnerability occurs when an application allows users to be redirected to an external, untrusted URL without validating the redirection target. By controlling the Host header and observing a redirection to the specified external site, you may have found an open redirect vulnerability. STEP TO REPRODUCE: go to www.localizestaging.com and interpret then change host header .it will redirect to changed host header webisite ## Impact This vulnerability can be exploited for phishing attacks, where users are misled into visiting a malicious site that appears to be trusted. It could also be used to bypass security filters or conduct other malicious activities.
Actions
View on HackerOne
Report Stats
  • Report ID: 2828499
  • State: Closed
  • Substate: duplicate
  • Upvotes: 1
Share this report