Details
Alert ID 10094-1
Alert Type Passive
Status alpha
Risk Informational
CWE 200
WASC 13
Technologies Targeted All
Tags CWE-200
OWASP_2017_A03
OWASP_2021_A04
More Info Scan Rule Help

Summary

An ASP.NET ViewState was disclosed by the application/web server.

Solution

Manually confirm that the ASP.NET ViewState does not leak sensitive information, and that the data cannot be aggregated/used to exploit other vulnerabilities.

Other Info

References

Code

org/zaproxy/zap/extension/pscanrulesAlpha/Base64Disclosure.java