Hacker News new | ask | show | jobs
by abofh 3430 days ago
Wow, I don't even have a facebook account and that works. That feels like some XSS waiting to happen :/
1 comments

It's an open redirect, not XSS. It's a matter of debate whether an open redirect is a vulnerability or not.