PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://github.com/PlaceOS/auth/issues/36 | exploit third party advisory patch |
http://packetstormsecurity.com/files/164345/PlaceOS-1.2109.1-Open-Redirection.html | exploit vdb entry third party advisory |