Skip to content

Open Redirection Vulnerability #268

@hacip

Description

@hacip

There is no validation for the year and month variables line between 158-160 on default.aspx.cs.
Additionally, these parameters were used to build another variable named "rewrite", and the "rewrite" parameter is being used within a redirection. (Line 183 default.aspx.cs)

it can be used for redirecting the user to a malicious web page.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions