Babel contains an open redirect vulnerability via redirect.php in the newurl parameter. An attacker can use any legitimate site using Babel to redirect user to a malicious site, thus possibly obtaining sensitive information, modifying data, and/or executing unauthorized operations.
id: CVE-2019-1010290
info:
name: Babel - Open Redirect
author: 0x_Akoko
severity: medium
de
...