logo

Database

Description

The system does not validate that profile image URLs lead to a valid image, allowing partial paths or URLs to be placed that can be used to craft more complex attack vectors such as controlled redirects or CSRF.

Impact

Manipulate the application to send redirects to third-party pages and load content from unverified sources.

Recommendation

Validate that the URLs provided in the profile images lead to valid images.

Threat

Attacker with access to the application from the Internet.

Expected Remediation Time

⏱️ 60 minutes.

Fixes