Welcome Guest, Not a member yet? Register   Sign In
CSRF token value is editable by ZAP tool
#1

[eluser]vicky_ratnesh[/eluser]
Hi All,

I am facing a problem while doing one project. I have implemented CSRF functionality for my web pages. All are working fine... only we are able to edit the csrf_token values from a security testing tool [named ZAP tool] and able to append some malicious information and also able to post the form,which should not happen ideally. Is there anyway so that this csrf_token cookie can be non-editable or any other suggestion to avoid this..?


Many many thanks.






Theme © iAndrew 2016 - Forum software by © MyBB