An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://gitee.com/wgd0ay/wgd0ay/issues/I8WSD1 | third party advisory issue tracking exploit |