mirror of https://github.com/docusealco/docuseal
The redir parameter was passed directly to redirect_to without any validation, allowing redirects to arbitrary external URLs. Only allow relative paths (starting with /) to prevent abuse.pull/653/head
parent
744d45d2c5
commit
e295b17728
Loading…
Reference in new issue