The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Open redirection (DOM-based)

rajauzairabdullah | Last updated: Nov 03, 2022 10:56AM UTC

Findings: The application may be vulnerable to DOM-based open redirection. Data is read from window.location.href and passed to window.location.href. Static Analysis: Data is read from window.location.href and passed to window.location.href via the following statement: window.location.href= window.location.href.replace(/(cid_path..., "" ) I am confused to understand the exploit here

Liam, PortSwigger Agent | Last updated: Nov 03, 2022 12:07PM UTC