open redirect in https://slack.com

Disclosed: 2014-05-31 18:42:06 By ipk1 To slack
Unknown
Vulnerability Details
Navigate to Https://slack.com append "/link?url=url=http://bing.com" or enter any website of your choice with http:// vulnerable link https://slack.com/link?url=http://bing.com notice that user is redirected to bing.com without being validated or notified
Actions
View on HackerOne
Report Stats
  • Report ID: 6035
  • State: Closed
  • Substate: informative
  • Upvotes: 2
Share this report