327 – Insufficient data authenticity validation - Images
Description
The system does not validate that profile image URLs lead to a valid image, allowing partial paths or URLs to be placed that can be used to craft more complex attack vectors such as controlled redirects or CSRF.
Impact
Manipulate the application to send redirects to third-party pages and load content from unverified sources.
Recommendation
Validate that the URLs provided in the profile images lead to valid images.
Threat
Attacker with access to the application from the Internet.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: P
- Confidentiality (VC): N
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): N
- Integrity (SI): N
- Availability (SA): N
Threat 4.0
- Exploit maturity: X