Insecure page redirects

Overview

Open redirect is a vulnerability that occurs when an application can redirect the users to a URL contained within untrusted input. By modifying the untrusted input to a malicious site, an attacker may launch a phishing scam and steal user credentials.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Frequent

Incidence

How common is this issue?
29%16%
arrow down13%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
3 years10 months
arrow down69%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconData SecurityiconSharing and VisibilityiconA01:2021 – Broken Access Controlicon