Details
-
Bug
-
Status: Closed
-
Minor
-
Resolution: Fixed
-
5.1 EE SP4 (5.1.7), 5.2 EE SP2 (5.2.6)
-
All
Description
By altering the redirect parameters in an URL, a phisher can send an unsuspecting user to a malicious site when they hit certain return links or cancel buttons. Such actions should redirect only to the same IP or authorized IP addresses defined in portal(-ext).properties.
Attachments
Issue Links
- is related to
-
LPS-4821 Phishers can redirect users to an untrusted site
- Closed