Executive brief
A file-upload feature in a web application redirects authenticated users to external websites based on data from the user's browser request, without validating the destination. An attacker can craft a malicious request that causes another user's browser to be redirected to a phishing or malicious site after uploading a file, potentially leading to credential theft or malware distribution.
Technical details
This is an open redirect vulnerability in a file-upload handler that reflects the Referer header without origin validation. The vulnerable component accepts a Referer header value and uses it to redirect the authenticated client's browser to an arbitrary external URL. Attack preconditions include an authenticated user uploading a file, which can be triggered via a crafted link or form submission. An attacker can redirect victims to external phishing or malware sites by manipulating the Referer header. The vulnerability affects authenticated users and requires no special privilege or complex exploitation.
Affected products
- <UNKNOWN> <UNKNOWN>
Timeline
- 2026-09-11: disclosed