cve/2023/CVE-2023-47168.md
2024-05-25 21:48:12 +02:00

772 B

CVE-2023-47168

Description

Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=

POC

Reference

No PoCs from references.

Github