Open redirect vulnerability in SHIRASAGI v1.14.4 to v1.15.0 allows a remote unauthenticated attacker to redirect users to an arbitrary web site and conduct a phishing attack.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www.ss-proj.org/ | product vendor advisory |
https://github.com/shirasagi/shirasagi | third party advisory product |
https://www.ss-proj.org/support/928.html | exploit vendor advisory |
https://jvn.jp/en/jp/JVN86350682/index.html | third party advisory |