AtMail WebMail versions 4.61 and below suffer from an open redirection vulnerability.
e98f3482bcb28b5fc85e0687acfe6be3488d7802675e80b7a8ca0b8b8e57628d
[+] Title: AtMail WebMail Open Redirect Vulnerability
[+] Date: 2020/03/11
[+] Author: Lutfu Mert Ceylan
[+] Vendor Homepage: www.atmail.com
[+] Software: Atmail Cloud Hosted Email
[+] Tested on: Windows 10
[+] Versions: 4.61 and before
[+] Vulnerable Parameter: "redirect" (Get Method)
[+] Vulnerable File: /atmail/parse.pl
[+} Dork : inurl:/atmail/parse.pl or /mail/parse.pl
# Notes:
An open redirect is a vulnerability that occurs when an application
that takes a parameter and redirects a user to the parameter value
without any validation. This vulnerability is used for phishing
attacks for redirecting users to visit malicious sites without against
their will.
# PoC:
Example Open Redirect Payload: http://localhost/atmail/parse.pl?redirect=https://lutfumertceylan.com.tr