Vulnerability Name
Classifications
Severity
Cross-site Request Forgery in Login Form
PCI v3.2-6.5.9, CAPEC-62, CWE-352, HIPAA-164.306(a), ISO27001-A.14.2.5, WASC-9, OWASP 2013-A8, OWASP 2017-A5
Low
Form Hijacking
CWE-20, ISO27001-A.14.2.5, WASC-20, OWASP 2013-A1, OWASP 2017-A1
Low
Insecure JSONP Endpoint
CWE-20, ISO27001-A.14.2.5, WASC-15, OWASP 2013-A5, OWASP 2017-A1
Low
Insecure Reflected Content
CWE-16, ISO27001-A.14.2.5, WASC-15, OWASP 2013-A5, OWASP 2017-A1
Low
Open Redirection in POST method
CWE-601, ISO27001-A.14.2.5, WASC-38, OWASP 2013-A10, OWASP 2017-A5
Low
Reflected File Download
PCI v3.2-6.5.1, CAPEC-375, CWE-840, ISO27001-A.14.2.5, WASC-42, OWASP 2013-A1, OWASP 2017-A1
Low
Subresource Integrity (SRI) Hash Invalid
CWE-16, ISO27001-A.14.2.5, WASC-15
Low
Unexpected Redirect Response Body (Two Responses)
CWE-698, ISO27001-A.14.2.5, WASC-25
Low
User Controllable Cookie
CWE-20, ISO27001-A.14.2.5, WASC-20
Low
Version Disclosure (phpMyAdmin)
CAPEC-170, CWE-205, HIPAA-164.306(a), 164.308(a), ISO27001-A.14.2.5, WASC-13, OWASP 2013-A5, OWASP 2017-A6
Low
ViewState is not Encrypted
CWE-16, HIPAA-164.306(a), 164.308(a), ISO27001-A.14.2.5, WASC-15, OWASP 2017-A6
Low
Content Security Policy (CSP) Not Implemented
CWE-16, ISO27001-A.14.2.5, WASC-15
Best Practice