Description
Using input in a Location header may let an attacker abuse a trusted domain to send users to a malicious site.
Potential impact
This may enable phishing. If an authentication flow trusts the redirect, it may also allow OAuth code theft or bypass access restrictions.
Remediation
Use server-defined internal paths, or choose external URLs through fixed keys and an allow-list. Do not treat a path beginning with // and an external host as an internal path.
Examples
Before
php
<?php
header('Location: ' . $_GET['redirect']);
After
php
<?php
$next = ($_GET['redirect'] ?? '') === 'profile' ? '/profile' : '/';
header('Location: ' . $next);
Explanation:
- Before: Uses user-controlled data as the redirect destination.
- After: Chooses a server-defined internal path. External destinations, if needed, should also be selected through fixed keys and an allow-list; a
//external-host path is not an internal destination.