logo

191 Lack of data validation - Responses


Description

The response data of some requests are sent in subsequent requests, so when the values of these responses are changed to invalid data, subsequent requests take this erroneous information without any type of validation.


Impact

Compromise the integrity of the information requests that are processed by the server.


Recommendation

Validate at all times from the server the types of data that are entered into different types of fields in the application.


Threat

Attacker from intranet with access to the application.


Expected Remediation Time

60 minutes.


Score 4.0

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

  • Attack vector: A
  • Attack complexity: L
  • Attack Requirements: N
  • Privileges required: L
  • User interaction: N
  • Confidentiality (VC): N
  • Integrity (VI): L
  • Availability (VA): N
  • Confidentiality (SC): N
  • Integrity (SI): N
  • Availability (SA): N

Threat 4.0

  • Exploit maturity: X

Requirements


Fixes


Last updated

2024/02/15