Skip to content

Commit 8656f3c

Browse files
committed
#11242 Ensure that the source parameter can't include a subdomain redirect
1 parent c77c859 commit 8656f3c

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

pages/login/LoginHandler.inc.php

+1-1
Original file line numberDiff line numberDiff line change
@@ -143,7 +143,7 @@ function signOut($args, $request) {
143143

144144
$source = str_replace('@', '', $request->getUserVar('source'));
145145
if (isset($source) && !empty($source)) {
146-
$request->redirectUrl($request->getProtocol() . '://' . $request->getServerHost() . $source, false);
146+
$request->redirectUrl($request->getProtocol() . '://' . $request->getServerHost() . '/' . $source, false);
147147
} else {
148148
$request->redirect(null, $request->getRequestedPage());
149149
}

0 commit comments

Comments
 (0)