The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://thycotic.com/products/secret-server/resources/advisories/thy-ss-009/ | vendor advisory |