Quiz 14 Question 19 of 20

During a web application penetration test, a tester discovers that the application includes user-supplied input in an HTTP redirect URL parameter without validation: https://app.com/redirect?url=https://victim.com. What vulnerability is present and what is the risk?

Select an answer to reveal the explanation.

Motivation