Skip to content

MASWE-0087: Análise e Escape Inseguros

Content in BETA

This content is in beta and still under active development, so it is subject to change any time (e.g. structure, IDs, content, URLs, etc.).

Send Feedback

Placeholder Weakness

This weakness hasn't been created yet and it's a placeholder. But you can check its status or start working on it yourself. If the issue has not yet been assigned, you can request to be assigned to it and submit a PR with the new content for that weakness by following our guidelines.

Check our GitHub Issues for MASWE-0087

Initial Description or Hints

ex. ataques XML External Entity (XXE), análise de certificados X509, escape de caracteres.

Relevant Topics

  • O aplicativo não realiza escape ou codificação adequada de caracteres especiais ao lidar com formatos de saída estruturados (ex. HTML, XML, JSON), o que pode levar a problemas de injeção ou renderização em componentes downstream (CWE-116).
  • O aplicativo analisa entrada XML sem restringir a resolução de entidades externas, permitindo ataques XML External Entity (XXE) que podem expor arquivos, iniciar SSRF ou interromper a lógica do aplicativo (CWE-611).

MASTG v1 Coverage

No MASTG v1 tests are related to this weakness.