A10 – Unvalidated Redirects and Forwards

Disclosed: 2017-11-09 13:08:19 By romanshyadav To infogram
Low
Vulnerability Details
https://infogram.com/login Web applications frequently redirect and forward users to other pages and websites, and use untrusted data to determine the destination pages. Without proper validation. when i intercept the twitter request and change it to the google then it will redirect you to the google. application should also verify the original request from the browser.
Actions
View on HackerOne
Report Stats
  • Report ID: 283269
  • State: Closed
  • Substate: informative
Share this report