Lack of data validation - Responses
Description
The response data of some requests are sent in subsequent requests, so when the values of these responses are changed to invalid data, subsequent requests take this erroneous information without any type of validation.
Impact
Compromise the integrity of the information requests that are processed by the server.
Recommendation
Validate at all times from the server the types of data that are entered into different types of fields in the application.
Threat
Attacker from intranet with access to the application.
Expected Remediation Time
⏱️ 60 minutes.