Skip to content

if "\@" in url ,the redirect result doesn't match the host of the new url("") #1800

@FDrag0n

Description

@FDrag0n

this.set('Location', encodeUrl(url))

image

Developer often use new url("") host to verify the redirected url, but here the encodeurl will cause the host verification to fail, thus creating a URL hopping vulnerability

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions