Details
Alert Id 10032-4
Alert Type Passive
Status release
Risk High
CWE 642
WASC 14
Technologies Targeted All
Tags CWE-642
OWASP_2017_A06
OWASP_2021_A04

Summary

This website uses ASP.NET’s Viewstate but maybe without any MAC.

Solution

Ensure the MAC is set for all pages on this website.

Other Info

References

Code

org/zaproxy/zap/extension/pscanrules/ViewstateScanRule.java