Details
Alert ID 210013-7
Alert Type Tool
Status alpha
Risk Medium
CWE 200
WASC
Technologies Targeted All
Tags CWE-200
OWASP_2021_A02
OWASP_2025_A04
TOOL_PTK

Summary

Tainted data embedded into image src URL for beacon-style exfiltration.

Generated by OWASP PTK IAST Module

Solution

• Do not send secrets or tokens to untrusted endpoints. • Validate destination URLs and strip sensitive headers/body fields. • Apply client-side DLP checks for outbound requests.

Other Info

References

Code

src/ptk/background/iast/modules/modules.json