Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7258
HistoryAug 08, 2018 - 6:22 a.m.

Open Redirection

2018-08-0806:22:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.001 Low

EPSS

Percentile

48.3%

github.com/gogs/gogs is vulnerable to open redirection attacks. The isValidRedirect function in routes/user/auth.go does not validate the initial /\\ substring in the URL, which allows remote attackers to redirect users to malicious websites and perform phishing attacks via the redirect_to parameter in user/login.

CPENameOperatorVersion
github.com/gogs/gogseqHEAD

0.001 Low

EPSS

Percentile

48.3%