The application passes sensitive parameters in the URL line of many of the requests.
BUSINESS IMPACT: Sensitive data could be disclosed unintentionally through transmission in the URL.
Description
The application uses the URL to pass sensitive data from the client to the server. Data passed in the URL can be exposed because data passed in this manner ends up in unintended locations. These locations can include server logs, local browser history, and proxy logs.
Reproduction Steps
Affected Locations
Recommendation
References
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.