.. / CVE-2020-13121

Exploit for Submitty <= 20.04.01 - Open Redirect (CVE-2020-13121)

Description:

Submitty through 20.04.01 contains an open redirect vulnerability via authentication/login?old= during an invalid login attempt. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2020-13121.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-13121.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-13121
https://github.com/ARPSyndicate/kenzer-templates
https://github.com/Submitty/Submitty/issues/5265