ViewState not encrypted
Description
The state information of application forms that is stored in the ViewState is not encrypted.
Impact
Leak app state information through the ViewState value.
Recommendation
Encrypt the ViewState in the application configuration.
Threat
Anonymous attacker with local access to the victims browser.
Expected Remediation Time
⏱️ 15 minutes.
Requirements
026 - Encrypt client-side session information