Description
Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated attackers can craft malicious billing URLs to redirect users to attacker-controlled domains for phishing and credential harvesting.
Problem types
URL Redirection to Untrusted Site ('Open Redirect')
Product status
Any version before 12.128.2
12.128.2 (semver)
Credits
Judel777
References
github.com/.../capgo/security/advisories/GHSA-grc7-98pf-h8hq (GHSA Advisory GHSA-grc7-98pf-h8hq)
www.vulncheck.com/...ect-via-unvalidated-stripe-billing-urls (VulnCheck Advisory: Capgo - Open Redirect via Unvalidated Stripe Billing URLs)