191 – Lack of data validation - Responses
Description
The response data of some requests are sent in subsequent requests, so when the values of these responses are changed to invalid data, subsequent requests take this erroneous information without any type of validation.
Impact
Compromise the integrity of the information requests that are processed by the server.
Recommendation
Validate at all times from the server the types of data that are entered into different types of fields in the application.
Threat
Attacker from intranet with access to the application.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: A
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): N
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X