mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-03 04:38:03 +02:00
718 B
718 B
CVE-2019-13038
Description
mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
POC
Reference
- https://github.com/Uninett/mod_auth_mellon/issues/35#issuecomment-503974885
- https://www.oracle.com/security-alerts/cpuapr2022.html
Github
No PoCs found on GitHub currently.