Skip to content

Rebase-triage-efforts#4

Open
cx-sean-casey wants to merge 2 commits intomasterfrom
rebase-triage-efforts
Open

Rebase-triage-efforts#4
cx-sean-casey wants to merge 2 commits intomasterfrom
rebase-triage-efforts

Conversation

@cx-sean-casey
Copy link
Owner

No description provided.

@cx-sean-casey
Copy link
Owner Author

cx-sean-casey commented Feb 26, 2025

Logo
Checkmarx One – Scan Summary & Detailsf2caaff2-fd43-40cf-9e46-c068589cfa0b

New Issues (5)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL Stored_XSS /WebGoat/Content/StoredXSS.aspx.cs: 49
detailsThe method LoadComments embeds untrusted data in generated output with Text, at line 52 of /WebGoat/Content/StoredXSS.aspx.cs. This untrusted data ...
Attack Vector
HIGH Reflected_XSS /WebGoat/WebGoatCoins/ProductDetails.aspx: 19
detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 19 of /WebGoat/WebGoatCoins/ProductDetails.aspx. This ...
Attack Vector
HIGH Reflected_XSS /WebGoat/WebGoatCoins/CustomerLogin.aspx: 9
detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 9 of /WebGoat/WebGoatCoins/CustomerLogin.aspx. This un...
Attack Vector
MEDIUM Missing_HSTS_Header /WebGoat/Resources/Master-Pages/Site.Master: 28
detailsThe web-application does not define an HSTS header, leaving it vulnerable to attack.
Attack Vector
LOW Unpinned Actions Full Length Commit SHA /main.yml: 29
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA helps...
Fixed Issues (130)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL SQL_Injection /WebGoat/WebGoatCoins/ForgotPassword.aspx.cs: 67
CRITICAL SQL_Injection /WebGoat/Content/ForgotPassword.aspx.cs: 66
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 266
CRITICAL Stored_XSS /WebGoat/App_Code/DB/SqliteDbProvider.cs: 258
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 266
CRITICAL Stored_XSS /WebGoat/App_Code/DB/SqliteDbProvider.cs: 258
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 266
CRITICAL Stored_XSS /WebGoat/App_Code/DB/SqliteDbProvider.cs: 258
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 266
CRITICAL Stored_XSS /WebGoat/App_Code/DB/SqliteDbProvider.cs: 258
CRITICAL Stored_XSS /WebGoat/App_Code/DB/SqliteDbProvider.cs: 258
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 266
CRITICAL Stored_XSS /WebGoat/App_Code/DB/SqliteDbProvider.cs: 258
CRITICAL Stored_XSS /WebGoat/App_Code/DB/MySqlDbProvider.cs: 266

More results are available on the CxOne platform

Policy Management Violations (1)

Policy Name: test3
  • Rule Name: no highs
    Scanner: SAST
    Entity: Vulnerability
    Conditions(s): High > 1

    Severity Issue Source File / Package Checkmarx Insight
    HIGH HttpOnly_Cookie_Flag_Not_Set_In_Config /WebGoat/Web.config: 45
    detailsThe /WebGoat/Web.config application configuration file, at line 45, does not define sensitive application cookies with the "httpOnly" flag, which c...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/ProductDetails.aspx: 19
    detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 19 of /WebGoat/WebGoatCoins/ProductDetails.aspx. This ...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/CustomerLogin.aspx: 9
    detailsThe method Checkmarx_Container embeds untrusted data in generated output with Write, at line 9 of /WebGoat/WebGoatCoins/CustomerLogin.aspx. This un...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/SQLInjectionDiscovery.aspx.cs: 27
    detailsThe method btnFind_Click embeds untrusted data in generated output with Text, at line 30 of /WebGoat/Content/SQLInjectionDiscovery.aspx.cs. This un...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/Orders.aspx.cs: 62
    detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 83 of /WebGoat/WebGoatCoins/Orders.aspx.cs. This untrusted data i...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/PathManipulation.aspx.cs: 33
    detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 43 of /WebGoat/Content/PathManipulation.aspx.cs. This untrusted d...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/ReflectedXSS.aspx.cs: 20
    detailsThe method LoadCity embeds untrusted data in generated output with Text, at line 26 of /WebGoat/Content/ReflectedXSS.aspx.cs. This untrusted data i...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/HeaderInjection.aspx.cs: 33
    detailsThe method Page_Load embeds untrusted data in generated output with Text, at line 33 of /WebGoat/Content/HeaderInjection.aspx.cs. This untrusted da...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/WebGoatCoins/Orders.aspx.cs: 114
    detailsThe method GridView1_RowDataBound embeds untrusted data in generated output with Text, at line 114 of /WebGoat/WebGoatCoins/Orders.aspx.cs. This un...
    Attack Vector
    HIGH Reflected_XSS /WebGoat/Content/UploadPathManipulation.aspx.cs: 26
    detailsThe method btnUpload_Click embeds untrusted data in generated output with Text, at line 26 of /WebGoat/Content/UploadPathManipulation.aspx.cs. This...
    Attack Vector
    HIGH XPath_Injection /WebGoat/Content/XPathInjection.aspx.cs: 20
    detailsThe application's FindSalesPerson method constructs an XPath query, for navigating an XML document. The XPath query is created with BinaryExpr, at ...
    Attack Vector

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant