Open Redirect Protection Bypass

Disclosed: 2017-12-23 07:48:36 By avinash_ To x
Unknown
Vulnerability Details
Hi Report #281538 is fixed but Attacker can Bypass this Open Redirect Protection. Give this link ``` https://twitter.com/teams/authorize?target_screen_name=&authorize_callback=//www.facebook.com``` to authorized victim.Twitter will say him to authorize a different account for create team.After authorization victim will be redirected to ```www.facebook.com``` Vulnerable point ```//www.facebook.com``` (You can use //www.example.com ) Open Redirection Protection Bypassed. PoC video attached With Best Regards
Actions
View on HackerOne
Report Stats
  • Report ID: 283460
  • State: Closed
  • Substate: resolved
  • Upvotes: 24
Share this report