Password Reset Link Poisoning

Password reset link poisoning in C#

Description

Building the domain of a password reset link from an attacker-controlled Request.Host or Host header can cause a link containing the attacker's domain to be sent. If the user opens that link, the reset token can be disclosed to the attacker.

Potential impact

  • Hijacked account recovery links, exposed password reset tokens, and account takeover.

Remediation

Build reset links from a public base URL in trusted configuration. Do not use the request's Host header to construct them.

Examples

Here, scheme and host come from the request, while configuredBaseUrl is an administrator-configured HTTPS base URL. resetToken is already encoded for use as a query parameter.

Before

csharp
var resetLink = $"{scheme}://{host}/reset-password?token={resetToken}";

After

csharp
var resetLink = $"{configuredBaseUrl}/reset-password?token={resetToken}";

Explanation:

  • Before: Building password reset links from request host data lets an attacker poison account recovery links with a malicious domain.
  • After: Build account recovery links from a trusted, configured base URL rather than Request.Host or the raw Host header.

References