Open Redirect in collectiveaccess/providence


Reported on

Nov 19th 2021


I find a way to bypass the Open Redirect at the login page with the "redirect" parameter.

Vulnerable parameter



Proof of Concept

Send users the following login link
After users use their registered account to log in, they will be redirected to


This functionality is not restricted to relative URLs within the application and could be leveraged by an attacker to fool an end-user into believing that a malicious URL they were redirected to is valid. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

We are processing your report and will contact the collectiveaccess/providence team within 24 hours. 2 years ago
We have contacted a member of the collectiveaccess/providence team and are waiting to hear back 2 years ago
CollectiveAccess validated this vulnerability 2 years ago
khanhchauminh has been awarded the disclosure bounty
The fix bounty is now up for grabs
CollectiveAccess marked this as fixed with commit 3e429d 2 years ago
CollectiveAccess has been awarded the fix bounty
to join this conversation