Skip to content
This repository was archived by the owner on Jan 24, 2019. It is now read-only.

Fixes: #456 #427#457

Closed
krogon-dp wants to merge 1 commit into
bitly:masterfrom
krogon-dp:fix/456
Closed

Fixes: #456 #427#457
krogon-dp wants to merge 1 commit into
bitly:masterfrom
krogon-dp:fix/456

Conversation

@krogon-dp

Copy link
Copy Markdown

No description provided.

@ploxiln

ploxiln commented Sep 27, 2017

Copy link
Copy Markdown
Contributor

This has the same problem as #427 has: it does not validate the redirect url is acceptable, and enables what is called an "open redirect".

(#427 is a better version of this because it properly parses the request for the rd parameter.)

@krogon-dp krogon-dp closed this Oct 9, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants