Open Redirects: A Forgotten Vulnerability?, (Tue, Feb 24th)

SANS Internet Storm Center, InfoCON: green 2026-02-24

Summary:

In 2010, OWASP added "Unvalidated Redirects and Forwards" to its Top 10 list and merged it into "Sensitive Data Exposure" in 2013 [owasp1] [owasp2]. Open redirects are often overlooked, and their impact is not always well understood. At first, it does not look like a big deal. The user is receiving a 3xx status code and is being redirected to another URL. That target URL should handle all authentication and access control, regardless of where the data originated.

Link:

https://isc.sans.edu/diary/rss/32742

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

02/24/2026, 18:38

Date published:

02/24/2026, 13:04