Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(PHP-A1011) Audit required: Insecure use of logger #2

Open
Gipfel opened this issue Jul 5, 2022 · 0 comments
Open

(PHP-A1011) Audit required: Insecure use of logger #2

Gipfel opened this issue Jul 5, 2022 · 0 comments

Comments

@Gipfel
Copy link
Owner

Gipfel commented Jul 5, 2022

Description

Logging user-provided values directly can put application vulnerable to multiple attack vectors. Superglobal variables contains values specified by the user, which are considered as tainted and untrusted. Therefore, it is discouraged to pass these variables directly to the logger.

Occurrences

There is 1 occurrence of this issue in the repository.

See all occurrences on DeepSource → deepsource.io/gh/Gipfel/PHP-Webinterface-MySQL/issue/PHP-A1011/occurrences/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant