Page tree

A security risk has been discovered on the SAM functionality, whereby malicious actors were using the SAM redirection link to point users to fraudulent sites, hidden behind a valid-looking url. This security risk only applies to customers using the "redirectTo" parameter in the email campaign link.

To address this risk, the SAM functionality will now only allow redirections to trusted sites that are whitelisted in the backend point of sales configuration. This list can be found on the "Gravity" tab, as shown below:

The list consists of a single domain per line. To allow a SAM redirection to an external site, the domain of the site must appear in this list. Access is also authorized for subdomains of those listed here.

If left empty, redirections will only be allowed to the domain of this point of sale (including subdomains).

For example, to authorize redirections to https://secutix.com, the list must include secutix.com. Subdomains, such a subdomain.secutix.com will also be authorized.

Please notice this list is exported in the catalog and as such is only applied once the web shop has resynchronized, which can take a few minutes.