Project

General

Profile

Actions

Bug #6249

closed

Login redirect to invalid URLs

Added by krileon about 8 years ago. Updated almost 8 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Start date:
17 October 2016
Due date:
% Done:

100%

Estimated time:

Description

Login redirect seams to be allowing redirect to URLs it shouldn't. For example if you're letting it return to the previous location then the previous location URL should be verified that it even makes sense. You shouldn't be able to login redirect to the confirmation page or registration page for example.

https://www.joomlapolis.com/forum/255-developer-members-support/235024-error-first-login#286982

Actions

Also available in: Atom PDF