endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

a vulnerability (CWE-79) #102

Open zisanyavuz opened 9 months ago

zisanyavuz commented 9 months ago

A medium severity vulnerability has been discovered in your project.

Project Name: sonarqube-1

Scanner Name: testing2

Cwe ID: 79

Cwe Name: Improper Neutralization of Input During Web Page Generation (Cross Site Scripting)

Cwe Link: https://cwe.mitre.org/data/definitions/79.html

Target: https://kondukto.com/index.html?name="JohnDoe"&address="here"

HTTP Request:

HTTP request content

HTTP Response:

HTTP response content

Kondukto Remediation 1: remediation

Tool Description: might be harmful, better be cautious

Discovered By: canbilgin@gmail.com

Custom Description: qq

Kondukto Link: http://10.20.104.4/projects/65c0e0844d94d54eabbd983e/vulns/appsec?page=1&perPage=15&id=in:65c229c1b75fc22a5838ea97 Deeplink: There is no available deeplink