What is CWE-698?
The web application sends a redirect to another location, but instead of exiting, it executes additional code.
Analyzing data...
The web application sends a redirect to another location, but instead of exiting, it executes additional code.
Analyzing data...
The web application sends a redirect to another location, but instead of exiting, it executes additional code.
| Impact | Scope | Explanation |
|---|---|---|
| Alter Execution Logic, Execute Unauthorized Code or Commands | Other, Confidentiality, Integrity, Availability | This weakness could affect the control flow of the application and allow execution of untrusted code. |
| Method | Approach | Effectiveness |
|---|---|---|
| Black Box | This issue might not be detected if testing is performed using a web browser, because the browser might obey the redirect and move the user to a different page before the application has produced outputs that indicate something is amiss. | — |
Below are representative vulnerabilities related to this CWE, prioritized by severity.
CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScanen