satyamchaurasiapersistent / JavaVulnerableLab

lab
0 stars 0 forks source link

CX Open_Redirect @ src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java [master] #93

Closed satyamchaurasiapersistent closed 2 years ago

satyamchaurasiapersistent commented 2 years ago

Open_Redirect issue exists @ src/main/java/org/cysecurity/cspf/jvl/controller/LoginValidator.java in branch master

The potentially tainted value provided by ""password"" in src\main\java\org\cysecurity\cspf\jvl\controller\LoginValidator.java at line 44 is used as a destination URL by sendRedirect in src\main\java\org\cysecurity\cspf\jvl\controller\LoginValidator.java at line 68, potentially allowing attackers to perform an open redirection.

Severity: Low

CWE:601

Vulnerability details and guidance

Checkmarx

Training Recommended Fix

Lines: 43 44


Code (Line #43):

       String user=request.getParameter("username").trim();

Code (Line #44):

          String pass=request.getParameter("password").trim();

satyamchaurasiapersistent commented 2 years ago

Issue still exists.

satyamchaurasiapersistent commented 2 years ago

Issue still exists.

satyamchaurasiapersistent commented 2 years ago

Issue still exists.