A10 – Unvalidated Redirects and Forwards
Low
Vulnerability Details
https://infogram.com/login
Web applications frequently redirect and forward users to other pages and websites, and use untrusted data to determine the destination pages. Without proper validation.
when i intercept the twitter request and change it to the google then it will redirect you to the google.
application should also verify the original request from the browser.
Actions
View on HackerOneReport Stats
- Report ID: 283269
- State: Closed
- Substate: informative