FirstBlood-#1011 — Open Redirect on logout.php
This issue was discovered on FirstBlood v3
On 2022-12-08, didsec Level 5 reported:
The ref
parameter is still vulnerable to open redirect on /drpanel/logout.php
it turns out that fix was not sufficient and I was able to bypass the fix by adding %09
Payload
?ref=/%09/attacker.com
To reproduce :
Visit: https://9ec4e8d7f009-didsec.a.firstbloodhackers.com/drpanel/logout.php?ref=/%09/attacker.com
Impact:
Attackers can serve malicious websites to attempt launching a phishing scam and steal user credentials. Because the server name in the modified link is identical to the original site, phishing attempts may have a more trustworthy appearance.
P4 Low
FirstBlood ID: 68
Vulnerability Type: Open Redirect
The open redirect on /drpanel/logout.php remains unfixed
Creator & Administrator
Congratulations you were the first to discover this bug! :-)