Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/42157 | third party advisory vdb entry |
http://holisticinfosec.org/content/view/62/45/ | broken link |