Skip to content

Cross-site Scripting (XSS) via redirect

Moderate
P0cas published GHSA-f37c-pvv3-7mfw Jan 3, 2022

Package

No package listed

Affected versions

1.46.0, 1.45.13, 1.45.12

Patched versions

1.46.1

Description

Summary

This Account Takeover via Dom XSS vulnerability occurs because the backend does not check the value of the redirect parameter in the login logic.

Impact

An attacker could use this vulnerability to take over a user account.

References

Severity

Moderate

CVE ID

CVE-2021-3837

Weaknesses

Credits