satyamchaurasiapersistent / JavaVulnerableLab

lab
0 stars 0 forks source link

CX Cross_Site_History_Manipulation @ src/main/webapp/admin/adminlogin.jsp [master] #90

Closed satyamchaurasiapersistent closed 2 years ago

satyamchaurasiapersistent commented 2 years ago

Cross_Site_History_Manipulation issue exists @ src/main/webapp/admin/adminlogin.jsp in branch master

Method if at line 20 of src\main\webapp\admin\adminlogin.jsp may leak server-side conditional values, enabling user tracking from another website. This may constitute a Privacy Violation.

Severity: Low

CWE:203

Vulnerability details and guidance

Checkmarx

Training Recommended Fix

Lines: 20 8


Code (Line #20):

                                   if(rs != null && rs.next()){

Code (Line #8):

if(request.getParameter("Login")!=null)

satyamchaurasiapersistent commented 2 years ago

Issue still exists.

satyamchaurasiapersistent commented 2 years ago

Issue still exists.

satyamchaurasiapersistent commented 2 years ago

Issue still exists.

satyamchaurasiapersistent commented 2 years ago

Issue still exists.