Skip to content

bypass of manageRedirect

Moderate
trasher published GHSA-gxv6-xq9q-37hg May 5, 2020

Package

glpi-project/glpi

Affected versions

< 9.4.6

Patched versions

9.4.6

Description

I have found a bypass to your Open Redirect protection based on a regexp (

static function manageRedirect($where) {
).

Just follow: http://HOST/index.php?redirect=/\/example.com

The location is rewrited to /\\/example.com which actually leads to example.com (tested on Chrome and Firefox).

Patches

Fixed in 5a74983

Reference

https://offsec.almond.consulting/multiple-vulnerabilities-in-glpi.html

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2020-11034

Weaknesses

No CWEs