Go to http://localhost/seeddms/out/out.Login.php?referuri=https://google.com
Or put any URL in the URL parameter referuri
.
Login with user credentials
In my case: UserID
= aman
`Password` = amanp
`Language` = English (GB)
Click Sign in
.
User will get redirected to the attacker's site. In our example to https://google.com
<aside> 📎 Note: This works for the Admin as well. Just enter Admin credentials as admin:admin
</aside>
[POC] SeedDMS - OpenRedirect.mp4