The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/e880a9fb-b089-4f98-9781-7d946f22777e | product third party advisory vdb entry exploit technical description |