logo

324 Control redirects


Summary

Redirects must be controlled, especially when they depend on external input.


Description

Systems must guarantee that all redirects lead to a controlled or trusted site. In general, redirects based on input data should be avoided as they could enable phishing attacks. If they are required, they should be controlled so that users are only redirected to trusted sites.


Supported In

Essential: True

Advanced: True


References


Weaknesses


Last updated

2024/02/05