Details
Alert Id 10040
Alert Type Passive Scan Rule
Status release
Risk
CWE
WASC

Summary

The page includes mixed content, that is content accessed via HTTP instead of HTTPS.

Solution

A page that is available over SSL/TLS must be comprised completely of content which is transmitted over SSL/TLS. The page must not contain any content that is transmitted over unencrypted HTTP. This includes content from third party sites.

References

Code

org/zaproxy/zap/extension/pscanrules/MixedContentScanRule.java