Open Redirect in ikus060/rdiffweb
Reported on
Nov 29th 2021
Description
ikus060/rdiffweb is vulnerable to open redirect at login page.
Proof of Concept
https://rdiffweb-demo.ikus-soft.com/login/?redirect=https://attacker.com
after login to the above url it redirect to attacker .com
Impact
This vulnerability is capable of redirecting to malicious website