Unsanitized user input in HTTP request (SSRF)
Overview
Description
Remediation Guidelines
new URL(request.getParameter("someRandomUrl")).getContent(); // unsafeString url; if (request.getParameter("selectedUrl").equals("option1")) { url = "https://api1.com"; } else { url = "https://api2.com"; }
References
Configuration
PreviousUnsanitized user input in format string detectedNextUnsanitized user input in HTTP response (XSS)
Last updated