Details
Alert Id 10032-5
Alert Type Passive
Status release
Risk High
CWE 642
WASC 14
Tags OWASP_2017_A06
OWASP_2021_A04

Summary

*** EXPERIMENTAL *** This website uses ASP.NET’s Viewstate but without any MAC.

Solution

Ensure the MAC is set for all pages on this website.

References

Code

org/zaproxy/zap/extension/pscanrules/ViewstateScanRule.java