An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://github.com/gnuboard/gnuboard5/issues/320 | issue tracking exploit vendor advisory |
https://sir.kr/g5_pds/7205 | patch |