CCSP Exam QuestionsBrowse all questions from this exam

CCSP Exam - Question 78


Which of the following threat types can occur when an application does not properly validate input and can be leveraged to send users to malicious sites that appear to be legitimate?

Show Answer
Correct Answer: A

Unvalidated redirects and forwards occur when an application does not properly validate input that controls the destination of a redirect or forward. This allows attackers to craft malicious URLs that redirect users to unwanted or malicious sites, making them appear legitimate. This type of threat can lead users to phishing sites or sites hosting malware, leveraging the trust users have in the application to validate their navigation.

Discussion

3 comments
Sign in to comment
akg001Option: A
Nov 18, 2024

A. Unvalidated redirects and forwards

MaciekMTOption: A
Feb 18, 2025

When an application doesn't validate input properly, it may inadvertently allow attackers to craft URLs that redirect users to malicious sites. This is known as unvalidated redirects and forwards, and it poses a significant risk because users might be tricked into believing they're navigating within a legitimate environment.

SCha81Option: A
Mar 9, 2025

Unvalidated redirects and forwards occur when an application does not properly validate user input before redirecting or forwarding requests. Attackers exploit this weakness to redirect users to malicious sites that appear legitimate, leading to phishing attacks, malware downloads, or credential theft.