Injection: Reflected URL Parameter¶
Identifier:
reflected_url_parameter
Scanner Support¶
| GraphQL Scanner | REST Scanner | WebApp Scanner | ASM Scanner | Automated Pentest |
|---|---|---|---|---|
Description¶
User input via URL parameters that is reflected in page content can indicate potential vulnerabilities, especially if the input isn't properly validated or sanitized.
How we test: We inject test payloads into URL parameters and analyze responses to detect if user input is reflected in page content without proper encoding or sanitization, which could indicate potential injection vulnerabilities.
Configuration¶
Example¶
Example configuration:
Reference¶
skip¶
Type: boolean
Skip the test if true.