Improper Input Validation Allows Malformed or Malicious Input

XMLWordPrintable

    • Type: Bug
    • Resolution: Done
    • Priority: Highest
    • 3.6.0
    • Affects Version/s: 3.4.0

      The application does not properly validate user-supplied input in https://uatamrit.piramalswasthya.org/ecd/supervisor/innerpage-supervisor?data=smsTemplate. Improper input validation can lead to security issues such as SQL injection, XSS (Cross-Site Scripting), command injection, or application crashes.

      Vulnerability Name Vulnerable Point, Port or Parameter CVE/CWE CVSS Score Overall Risk
      (Severity)
      Mapping with OWASP Testing Checklist Observation / Description Impact Recommendation Reference Steps to reproduce
      Improper Input Validation https://uatamrit.piramalswasthya.org/ecd/supervisor/innerpage-supervisor?data=smsTemplate CWE-79 5.4 Medium OWASP Client Side Testing Allowing raw HTML input without proper validation increases the risk of future client-side vulnerabilities like stored XSS or UI manipulation
       
      Weak input validation may allow chaining with other attacks. Implement server-side validation to restrict HTML tags and unexpected input types.
       
      Sanitize all incoming user data using a secure whitelist approach.
      https://cheatsheetseries.owasp.org/cheatsheets/Input_Validation_Cheat_Sheet.html  

        1. image-2025-12-10-17-52-09-350.png
          36 kB
          Deep Shikha
        2. image-2025-12-10-17-52-36-397.png
          39 kB
          Deep Shikha
        3. image-2025-12-10-17-52-51-600.png
          129 kB
          Deep Shikha
        4. image-2025-12-10-17-53-05-896.png
          37 kB
          Deep Shikha
        5. image-2025-12-10-17-53-23-618.png
          131 kB
          Deep Shikha
        6. image-2025-12-10-17-53-36-122.png
          37 kB
          Deep Shikha
        7. image-2025-12-10-17-53-50-805.png
          154 kB
          Deep Shikha
        8. image-2025-12-10-17-54-03-563.png
          133 kB
          Deep Shikha
        9. Screenshot from 2025-11-12 12-58-38.png
          85 kB
          Amoghavarsh Desai
        10. Screenshot from 2025-11-12 12-59-45.png
          80 kB
          Amoghavarsh Desai
        11. Screenshot from 2025-11-12 13-00-14.png
          81 kB
          Amoghavarsh Desai

            Assignee:
            Deep Shikha
            Reporter:
            Shashank Kharkwal
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: