Open Redirect
Moderate severity
GitHub Reviewed
Published
Jun 29, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 20, 2021
Published to the GitHub Advisory Database
Jun 29, 2021
Last updated
Jan 9, 2023
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.
References