CVE-2024-4940 Information
Jun 23, 2024
cve
Description
An open redirect vulnerability exists in the gradio-app/gradio affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites which can be exploited for phishing attacks Cross-site Scripting (XSS) Server-Side Request Forgery (SSRF) amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that when processed by the application redirects the user to an attacker-controlled web page.
Reference
https://huntr.com/bounties/35aaea93-6895-4f03-9c1b-cd992665aa60
Share on: