Detected an open redirect vulnerability in Tiny Tiny RSS where the return parameter in public.php was abused to redirect users to an attacker-controlled external URL after the authentication flow.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view