CVE: 2016-3726
Step to reproduce
- Affected Param
back=
- Full URL
http://127.0.0.1/dg-user/?controller=authentification&back=http%3A%2F%2Fexploitlab.ex%2F
- Go to login page you will get this type of URL
- Now time for Redirect
- Change the
back= parm URL http://exploitlab.ex/dg-user/?controller=authentification&back=http%3a%2f%2fevil.com%2f
- Evil URL Like http://evil.com/ i encode the special charecter.
- Now enter the URL in browser and press enter you will see login page.
- Now Login using your email password
- You will redirected to http://evil.com
Hope it will fix soon.
Thanks & Regards,
Rudra Sarkar
CVE: 2016-3726
Step to reproduce
back=http://127.0.0.1/dg-user/?controller=authentification&back=http%3A%2F%2Fexploitlab.ex%2Fback=parm URL http://exploitlab.ex/dg-user/?controller=authentification&back=http%3a%2f%2fevil.com%2fHope it will fix soon.
Thanks & Regards,
Rudra Sarkar