Unvalidated URL redirects

Unvalidated URL redirects

Description

Using input in a Location header may let an attacker abuse a trusted domain to send users to a malicious site.

Potential impact

This may enable phishing. If an authentication flow trusts the redirect, it may also allow OAuth code theft or bypass access restrictions.

Remediation

Use server-defined internal paths, or choose external URLs through fixed keys and an allow-list. Do not treat a path beginning with // and an external host as an internal path.

Examples

Before

php
<?php
header('Location: ' . $_GET['redirect']);

After

php
<?php
$next = ($_GET['redirect'] ?? '') === 'profile' ? '/profile' : '/';
header('Location: ' . $next);

Explanation:

  • Before: Uses user-controlled data as the redirect destination.
  • After: Chooses a server-defined internal path. External destinations, if needed, should also be selected through fixed keys and an allow-list; a // external-host path is not an internal destination.

References