Open Redirect in https://www.usbr.gov/gp-bin/clickgo.pl?submit2=GO!&goto=google.com

Disclosed by
tonyverapo
  • Engagement Bureau of Reclamation
  • Disclosed date about 1 year ago
  • Priority P4 Bugcrowd's VRT priority rating
  • Status Resolved This vulnerability has been accepted and fixed
Summary by Bureau of Reclamation

The open redirect vulnerability was resolved, offending script deleted from the servers. A re-test by BugCrowd confirmed they were not able to reproduce.
Disclosure approved for the purpose of educating and raising awareness for the security community.

Summary by tonyverapo

An open redirect vulnerability exists on the website, allowing attackers to manipulate the "goto" parameter to redirect users to arbitrary domains. This vulnerability can be exploited for phishing attacks, leading users to malicious sites while appearing to come from a trusted source.

Activity