Users must not be able to define unauthorised virtual locations/addresses such as:
Database table names. File system paths. Alert SMS or email messages. URL paths. All such properties must be defined by the ecommerce application itself, or drawn from a valid list of locations permitted for the user and their role.
Tim can influence where data is sent or forwarded to
Owasp ASVS (4.0): 4.1.3 ,4.2.1 ,5.1.5
Capec: 153
Owasp SCP: 44
Owasp Appsensor:
Safecode: 8,10,11
ASVS V4.1 - General Access Control Design
ASVS V4.2 - Operation Level Access Control
ASVS V5.1 - Input Validation Requirements
Loading comments 0%