URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
The product misinterprets an input, whether from an attacker or another product, in a security-relevant fashion.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://huntr.dev/bounties/228d5548-1109-49f8-8aee-91038e88371c | third party advisory exploit |
https://github.com/medialize/uri.js/commit/88805fd3da03bd7a5e60947adb49d182011f1277 | third party advisory patch |