zurmo / Zurmo

GNU Affero General Public License v3.0
100 stars 41 forks source link

Open Redirect in RedirectUrl GET parameter #5

Open naxonez opened 8 years ago

naxonez commented 8 years ago

Hi,

I found this Open Redirect in ZurmoCRM.

[*] Page affected

index.php/meetings/default/edit?id=182&redirectUrl=http://www.google.com

[*] Fields affected

RedirectUrl

When you write any domain in the parameter RedirectURL the user is redirect to this url This attack can be used to do phishings or redirection to exploit kits.

Regards.