[+] Title: AtMail WebMail Open Redirect Vulnerability [+] Date: 2020/03/11 [+] Author: Lutfu Mert Ceylan [+] Vendor Homepage: www.atmail.com [+] Software: Atmail Cloud Hosted Email [+] Tested on: Windows 10 [+] Versions: 4.61 and before [+] Vulnerable Parameter: "redirect" (Get Method) [+] Vulnerable File: /atmail/parse.pl [+} Dork : inurl:/atmail/parse.pl or /mail/parse.pl # Notes: An open redirect is a vulnerability that occurs when an application that takes a parameter and redirects a user to the parameter value without any validation. This vulnerability is used for phishing attacks for redirecting users to visit malicious sites without against their will. # PoC: Example Open Redirect Payload: http://localhost/atmail/parse.pl?redirect=https://lutfumertceylan.com.tr