An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after a successful login.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://drive.google.com/file/d/1kSDlPASBCgJEINxTSIsjMWrU4u4T5XCc/view?usp=sharing | third party advisory exploit |
https://www.ilch.de/ | product |
https://github.com/xoffense/POC/blob/main/Ilch%202.1.42%20Open%20redirect | third party advisory exploit |