QID 150516
Date Published: 2022-08-25
QID 150516: Web Application External URL Redirection
External redirected links were discovered during the scan and are listed in the Results section.
Attackers can use external redirects without validation to redirect a user to a malicious URL. For example, if the trusted application is https://X.X.X.TrustQualys/test?url=qualys.com, the user is navigating to https://X.X.X.TrustQualys, and it is a trusted domain. However, there is an invalidated redirect, and the attacker can manipulate the redirection. The attacker can use this link https://X.X.X.TrustQualys/test?url=X.X.XReallyBadApp.com (for this example, ReallyBadApp is used, savvy malicious attackers will use more legitimate looking values) where the customer may be redirected to an external entity X.X.XReallyBadApp.com. This unintended redirect may lead to fishing or malware. Since the user was redirected from a trusted application, the user may be more willing to provide information.
CVEs related to QID 150516
| Advisory ID | Software | Component | Link |
|---|