Insecure functionality
Description
A functionality that is part of the system can be leveraged by an attacker in order to negatively impact it.
Impact
Change the password after the security code has been compromised.
Recommendation
Validate on the server side that the answers to the questions are correct.
Threat
Any customer of the organization authorized from the Internet.
Expected Remediation Time
⏱️ 60 minutes.
Requirements
266 - Disable insecure functionalitiesRules
Go Dynamic Unsafe ReflectionPhp Unsafe Reflection Dynamic CallScala Dynamic Unsafe ReflectionJava Code Download Without ValidationJava Unsafe Object BindingKotlin Expression Language InjectionJavascript Manual Csrf Token Handling FetchPython Untrusted Pickle File DeserializationJavascript Manual Csrf Token Handling XhrC Sharp Dynamic Unsafe ReflectionJavascript Manual Csrf Token Handling AjaxJava User Input Xquery InjectionJavascript Manual Csrf Token Handling AxiosScala Expression Language InjectionPython User Controlled Dynamic ImportRuby Unsafe Input Resource InjectionDart Mirrors Unsafe ReflectionKotlin Class Unsafe ReflectionTypescript Manual Csrf Token Handling AjaxTypescript Manual Csrf Token Handling FetchRuby Rails Mass AssignmentPython Markup Safe User InputTypescript Manual Csrf Token Handling AxiosTypescript Manual Csrf Token Handling Xhr