DhavalPatelPersistent / JavaVulnerableLabTest

0 stars 0 forks source link

CX Open_Redirect @ src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java [refs/heads/master] #5

Open github-actions[bot] opened 2 years ago

github-actions[bot] commented 2 years ago

Open_Redirect issue exists @ src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java in branch refs/heads/master

The potentially tainted value provided by ""password"" in src\main\java\org\cysecurity\cspf\jvl\controller\LoginValidator.java at line 44 is used as a destination URL by sendRedirect in src\main\java\org\cysecurity\cspf\jvl\controller\LoginValidator.java at line 68, potentially allowing attackers to perform an open redirection.

Severity: Low

CWE:601

Vulnerability details and guidance

Checkmarx

Training Recommended Fix

Lines: 43 44


Code (Line #43):

       String user=request.getParameter("username").trim();

Code (Line #44):

          String pass=request.getParameter("password").trim();

github-actions[bot] commented 2 years ago

Issue still exists.

github-actions[bot] commented 2 years ago

Issue still exists.

github-actions[bot] commented 2 years ago

Issue still exists.