You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Someone could form a link with a target that goes to their website (that looks like pdm or whatever).
I don't know what phishing you're going to do with pdm exactly given that all the players are penniless and we never ask you for anything worth phishing. But we should close the vulnerability on principle. Presumably we can either just use a path as target or ensure that target starts with https:://ourdomain?
Noticed by a bot on #13309 although that's not where the vulnerability was created.
There might be other target querystring params in other parts of the site, not sure.
The text was updated successfully, but these errors were encountered:
Someone could form a link with a target that goes to their website (that looks like pdm or whatever).
I don't know what phishing you're going to do with pdm exactly given that all the players are penniless and we never ask you for anything worth phishing. But we should close the vulnerability on principle. Presumably we can either just use a path as
target
or ensure thattarget
starts with https:://ourdomain?Noticed by a bot on #13309 although that's not where the vulnerability was created.
There might be other target querystring params in other parts of the site, not sure.
The text was updated successfully, but these errors were encountered: