info: name: Open Redirect in url_redirect Parameter author: ProjectDiscoveryAI severity: medium description: | Detects open redirect vulnerability in the `url_redirect` parameter, which can lead to malicious redirection. tags: openredirect,vulnerability
http: -raw: - | GET /?url_redirect=http://evil.com HTTP/1.1 Host: {{Hostname}}
matchers-condition: and matchers: -type: status status: -302 -301 -type: regex regex: -"(?i)http:\\/\\/evil\\.com" part: header