Welcome Guest, Not a member yet? Register   Sign In
CSRF token value is editable by ZAP tool

Hi All,

I am facing a problem while doing one project. I have implemented CSRF functionality for my web pages. All are working fine... only we are able to edit the csrf_token values from a security testing tool [named ZAP tool] and able to append some malicious information and also able to post the form,which should not happen ideally. Is there anyway so that this csrf_token cookie can be non-editable or any other suggestion to avoid this..?

Many many thanks.

Theme © iAndrew 2016 - Forum software by © MyBB