Description
Building the domain of a password reset link from an attacker-controlled Request.Host or Host header can cause a link containing the attacker's domain to be sent. If the user opens that link, the reset token can be disclosed to the attacker.
Potential impact
- Hijacked account recovery links, exposed password reset tokens, and account takeover.
Remediation
Build reset links from a public base URL in trusted configuration. Do not use the request's Host header to construct them.
Examples
Here, scheme and host come from the request, while configuredBaseUrl is an administrator-configured HTTPS base URL. resetToken is already encoded for use as a query parameter.
Before
csharp
var resetLink = $"{scheme}://{host}/reset-password?token={resetToken}";
After
csharp
var resetLink = $"{configuredBaseUrl}/reset-password?token={resetToken}";
Explanation:
- Before: Building password reset links from request host data lets an attacker poison account recovery links with a malicious domain.
- After: Build account recovery links from a trusted, configured base URL rather than
Request.Hostor the raw Host header.