Project

General

Profile

Actions

Bug #70

closed

Feature #65: Security Audit

[Security Audit ] 5 -Failed Defences Against Application Misuse

Added by Kalyan Battula about 1 year ago. Updated 7 months ago.

Status:
Closed
Priority:
High
Category:
-
Target version:
Start date:
17/04/2024
Due date:
% Done:

0%

Estimated time:
Deployed In:
Category:

Description

5 -Failed Defences Against Application Misuse
CWE : CWE-841
Description :
The misuse and invalid use of valid functionality can identify attacks attempting to
enumerate the web application, identify weaknesses, and exploit vulnerabilities. Tests
should be undertaken to determine whether there are application-layer defensive
mechanisms in place to protect the application.
Affected Path(s) :
https://earogya.satragroup.in/change-password *-Applicable to entire application
Impact :
The lack of active defences allows an attacker to hunt for vulnerabilities without any
recourse. The application’s owner will thus not know their application is under attack.
Recommendation :
Build inactive defences against application misuse. It is also recommended to implement
strong server side controls in such a way that same request cannot be submitted
multiple times.
Evidence/Proof Of Concept :
Step 1: Login to the application and submit change-password record and sumbit the
record.Again submit the same request multiple times. It was observed that the server accepts
it.


Files

clipboard-202404171537-0avjq.png (55.4 KB) clipboard-202404171537-0avjq.png Kalyan Battula, 17/04/2024 03:37 PM
Actions #1

Updated by Vasudev Mamidi 12 months ago

  • Assignee set to Vasu Malladi
Actions #2

Updated by Vasudev Mamidi 12 months ago

  • Assignee changed from Vasu Malladi to Vasudev Mamidi
Actions #3

Updated by Pavan kumar Siddamsetti 12 months ago

  • Status changed from New to In Progress
Actions #4

Updated by Vasudev Mamidi 12 months ago

  • Status changed from In Progress to Resolved
Actions #5

Updated by Sivakanth Kesiraju 12 months ago

  • Target version set to Sprint 1 (29th April - 3rd May)
Actions #6

Updated by Sivakanth Kesiraju 12 months ago

  • Target version changed from Sprint 1 (29th April - 3rd May) to Security Audit
Actions #7

Updated by Gautam Kumar 7 months ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF