Products.pluggableauthservice 2.6.0 open redirect Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2021-06-02 |
Type : webapps |
Platform : python
This exploit / vulnerability Products.pluggableauthservice 2.6.0 open redirect is for educational purposes only and if it is used you will do on your own risk!
--------------------------Proof of Concept-----------------------
1- Goto https://localhost/login
2- Turn on intercept and click on the login
3- Change "came_from" parameter value to https://attacker.com
4- User will be redirected to an attacker-controlled website.