WordPress Plugin Vulnerabilities

Newsletter Manager < 1.5 - Unauthenticated Open Redirect

Description

The plugin used base64 encoded user input in the appurl parameter without validation, to redirect users using the header() PHP function, leading to an open redirect issue

Proof of Concept

Affects Plugins

References

Classification

Type
REDIRECT
OWASP top 10
CWE

Miscellaneous

Original Researcher
posix
Submitter
posix
Verified
Yes

Timeline

Publicly Published
2019-05-18 (about 6 years ago)
Added
2019-05-21 (about 6 years ago)
Last Updated
2020-12-29 (about 5 years ago)

Other