translate / pootle

Online translation tool
http://pootle.translatehouse.org
GNU General Public License v3.0
1.49k stars 284 forks source link

Open Redirect On Login Page. #6906

Open ghost opened 4 years ago

ghost commented 4 years ago

Hello, I was doing a bug bounty for a company and stumbled upon an open redirect on the login page ~

Steps to reproduce:

Results (Expected/Actual):

User should be notified that they are leaving domain or shouldn't be redirected at-all. / Instead user gets redirected without any confirmation or notice. Portswigger refrence on open redirect: https://portswigger.net/kb/issues/00500100_open-redirection-reflected

Environment

Version: 2.8.2