Open Redirect
Open Redirect
Description
Example with Scenario
Payloads and Test Cases
/redirect?url=http://malicious.com/redirect?url=http%3A%2F%2Fmalicious.com/redirect?url=//malicious.com
/redirect?url=http://malicious.com# Send payload to the server sendPayloadToServer("/redirect?url=http://malicious.com") # Verify if the application redirects to the malicious URL checkRedirection("http://malicious.com")
/redirect?url=http%3A%2F%2Fmalicious.com# Send payload to the server sendPayloadToServer("/redirect?url=http%3A%2F%2Fmalicious.com") # Verify if the application redirects to the malicious URL checkRedirection("http://malicious.com")
/redirect?url=//malicious.com# Send payload to the server sendPayloadToServer("/redirect?url=//malicious.com") # Verify if the application redirects to the malicious URL checkRedirection("http://malicious.com")
Mitigation
Last updated