Otvoriť Uzavreté

LoggedOut Page XSS and SQL Injection Warnings from ZAP #3443


User avatar
0
jackmcelhinney vytvorené
  • ABP Framework version: v5.2.2
  • UI type: Angular w/ Authorization Code Flow
  • DB provider: EF Core
  • Identity Server Separated (Angular): no

After running the OWASP ZAP penetration test tool, the report shows 2 Cross Site Scripting (Reflected) warnings and 1 SQL Injection warning on the log-out page. These may be false warnings, but can these be resolved as this issue was?


4 odpoveď(e)/dí
  • User Avatar
    0
    maliming vytvorené
    Tím podpory Fullstack Developer

    hi

    We will check and fix this. Thanks.

  • User Avatar
    0
    maliming vytvorené
    Tím podpory Fullstack Developer

    Question Credits Refunded

  • User Avatar
    0
    maliming vytvorené
    Tím podpory Fullstack Developer

    I sent the changes to jack.xxx@xxxlarity.com.

  • User Avatar
    0
    jackmcelhinney vytvorené

    Received. Thanks!

Made with ❤️ on ABP v8.2.0-preview Updated on marca 25, 2024, 15:11