Fixing Open Redirect Vulnerability in .Net Framework 4.8 Web Forms

Viewed 221

I'm trying to fix Open Redirect Vulnerabilities detected by Fortify in my codebase which uses Response.Redirect(url) to do redirects.

The 'url' is built using some user inputs but the redirects are made locally in the application

After doing some research I found the checking if the url is local before calling the Response.Redirect() method can help fix the vulnerability - https://docs.microsoft.com/en-us/aspnet/mvc/overview/security/preventing-open-redirection-attacks#protecting-your-aspnet-mvc-10-and-mvc-2-applications

I tried using IsLocalUrl for Webforms - https://stackoverflow.com/a/71564449/6245235

But fortify still detects it as a Vulnerability. Do I need any additional checks?

0 Answers
Related