cx-justin-ruth / CxFlowGithub

0 stars 0 forks source link

CX Empty_Password_In_Connection_String @ root/product.jsp [master] #32

Open cx-justin-ruth opened 2 years ago

cx-justin-ruth commented 2 years ago

Empty_Password_In_Connection_String issue exists @ root/product.jsp in branch master

The application uses the empty password """" for authentication purposes, either using it to verify users' identities, or to access another remote system. This empty password is set at line 10 of root\product.jsp appears in the code, cannot be changed without rebuilding the application and indicates its associated account is exposed.

Severity: Low

CWE:259

Vulnerability details and guidance

Checkmarx

Lines: 10


Code (Line #10):

            val = 1;