endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

Change this code to not reflect user-controlled data. (CWE-79) #100

Open zisanyavuz opened 9 months ago

zisanyavuz commented 9 months ago

A high severity vulnerability has been discovered in your project.

Project Name: sonarqube-1

Scanner Name: sonarqube

Cwe ID: 79

Cwe Name: Improper Neutralization of Input During Web Page Generation (Cross Site Scripting)

Cwe Link: https://cwe.mitre.org/data/definitions/79.html

File: resetpassword.php

Line: 77

Code:

                    


Language: php

Kondukto Remediation 1: remediation

Tool Description: Change this code to not reflect user-controlled data.

Custom Description: test

Kondukto Link: http://10.20.104.4/projects/65c0e0844d94d54eabbd983e/vulns/appsec?page=1&perPage=15&id=in:65c0e2d951ea6303bf4dac9b Deeplink: http://10.20.104.48:9000/project/issues?types=VULNERABILITY&open=AYzyN3kgTftj40din2QY&id=php-tudo