PharmaLedger-IMI / epi-workspace

ePI use case main repository
MIT License
4 stars 0 forks source link

Veracode issue - LPWA js/utils/utils.js line 120 #1153

Open skutner opened 1 year ago

skutner commented 1 year ago

URL Redirection to Untrusted Site ('Open Redirect')

Description: This call to href() contains a URL redirection to untrusted site flaw. Writing untrusted input into a URL value could cause the web application to redirect the request to the specified URL, leading to phishing attempts to steal user credentials.

Remediation: Always validate untrusted input to ensure that it conforms to the expected format, using centralized data validation routines when possible.

salboaie commented 1 year ago

Try to change teh site using window.location.pathname