Open redirection in fabric.io

Disclosed: 2014-12-18 18:17:22 By avicoder_ To x
Unknown
Vulnerability Details
Hi dear, Once the person is logged into his account he can be redirected to any website . https://www.fabric.io/login?redirect_url=@<payload> for example : https://www.fabric.io/[email protected] Tested on updated firefox and chrome.
Actions
View on HackerOne
Report Stats
  • Report ID: 39631
  • State: Closed
  • Substate: resolved
  • Upvotes: 2
Share this report