Burp Suite User Forum

Create new post

Open redirection (DOM-based)

rajauzairabdullah | Last updated: Nov 03, 2022 10:56AM UTC

Findings: The application may be vulnerable to DOM-based open redirection. Data is read from window.location.href and passed to window.location.href. Static Analysis: Data is read from window.location.href and passed to window.location.href via the following statement: window.location.href= window.location.href.replace(/(cid_path..., "" ) I am confused to understand the exploit here

Liam, PortSwigger Agent | Last updated: Nov 03, 2022 12:07PM UTC

Thanks for your message. Could you send a screenshot of the full issue detail to support@portswigger.net, please?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.