Description
Using a user-supplied URL as a redirect destination can send users to an untrusted external site.
Potential impact
- Attackers can exploit a trusted domain for phishing, token theft or bypassing destination restrictions.
Remediation
Allow only local paths, or validate external destinations against an explicit list of trusted domains.
Examples
The first excerpt uses a Minimal API; the second belongs inside an MVC controller. Url, Redirect and LocalRedirect are controller APIs.
Before
csharp
return Results.Redirect(returnUrl);
After
csharp
if (!Url.IsLocalUrl(returnUrl)) {
return Redirect("/dashboard");
}
return LocalRedirect(returnUrl);
Explanation:
- Before: The user controls the redirect URL and can choose an attacker-controlled site.
- After:
Url.IsLocalUrlchecks the destination first. Only an allowed local path is passed toLocalRedirect.