DOM-based Link Manipulation

low Web App Scanning Plugin ID 115681

Synopsis

DOM-based Link Manipulation

Description

The page's client-side script uses a URL parameter value, without validation, as the target of a link or the `action` of a form.

Unlike an unvalidated redirection, nothing happens when the page loads: the victim must click the manipulated link or submit the form. Attackers abuse this in phishing and social engineering attacks to make a trusted page link to a malicious site, or to send form data to a server they control.

The scanner has discovered that an injected parameter value became the target of a link or form on the page.

Solution

Avoid building link or form targets from data supplied in the URL. Where this is required, validate the value against a whitelist of permitted pages, or only accept relative paths on the application's own origin and reject absolute and protocol-relative URLs.

See Also

https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html

Plugin Details

Severity: Low

ID: 115681

Type: Check Based

Published: 10/8/2026

Updated: 10/8/2026

Scan Template: full, pci, scan

Risk Information

CVSS v2

Risk Factor: Low

Base Score: 2.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Low

Base Score: 3.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Low

Base Score: 2.1

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information