FirstBlood-#1011Open Redirect on logout.php
This issue was discovered on FirstBlood v3



On 2022-12-08, didsec Level 5 reported:

The ref parameter is still vulnerable to open redirect on /drpanel/logout.php it turns out that fix was not sufficient and I was able to bypass the fix by adding %09

Payload

?ref=/%09/attacker.com

To reproduce :

  • Visit: https://9ec4e8d7f009-didsec.a.firstbloodhackers.com/drpanel/logout.php?ref=/%09/attacker.com

Impact:

Attackers can serve malicious websites to attempt launching a phishing scam and steal user credentials. Because the server name in the modified link is identical to the original site, phishing attempts may have a more trustworthy appearance.

P4 Low


FirstBlood ID: 68
Vulnerability Type: Open Redirect

The open redirect on /drpanel/logout.php remains unfixed

Report Feedback

@zseano

Creator & Administrator


Congratulations you were the first to discover this bug! :-)