perfact::mpa Open Redirect
Posted by deepcore on March 2, 2016 – 8:02 pm
The SySS GmbH found out that the web application perfact:mpa accepts user-controlled input via the URL parameter “redir” that can be used to redirect victims to an arbitrary site which simplifies so-called phishing attacks.
Post a reply
You must be logged in to post a comment.