CWE-698: Execution After Redirect (EAR)

What is CWE-698?

The web application sends a redirect to another location, but instead of exiting, it executes additional code.

Analyzing data...

Data statistics

RELATED CVES (365 DAYS)1
ABSTRACTIONBase

Vulnerabilities mapped to CWE-698

1 vulnerabilitiesNo change year over year

Vulnerabilities in CISA KEV for CWE-698

0 vulnerabilities

Official definition

ByMitre CWE

The web application sends a redirect to another location, but instead of exiting, it executes additional code.

Characteristics

Alternate terms

  • Redirect Without Exit

Modes of introduction

  • Implementation

Common consequences

ImpactScopeExplanation
Alter Execution Logic, Execute Unauthorized Code or CommandsOther, Confidentiality, Integrity, AvailabilityThis weakness could affect the control flow of the application and allow execution of untrusted code.

Detection methods

MethodApproachEffectiveness
Black BoxThis issue might not be detected if testing is performed using a web browser, because the browser might obey the redirect and move the user to a different page before the application has produced outputs that indicate something is amiss.—

Representative vulnerabilities

Sources (3)

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan