Invalidated redirects and forwards: A security vulnerability that allows attackers to redirect users to unintended destinations, potentially leading them to malicious websites or enabling them to steal sensitive information. Preventing this flaw is crucial in web application security to ensure users are not manipulated into visiting harmful sites. Common exploitations include phishing attacks and social engineering schemes that leverage fake login pages or deceptive links.
Categories: CC D5: Security Operations | CCSP D4: Cloud Application Security | CISM D3: Information Security Program | CISSP D8: Software Development Security | Security+ D2: Threats Vulnerabilities and Mitigations | SSCP D7: Systems and Application Security
« Back to Glossary Index