logo

Vulnerable By Design...no, Really

ID: 5a51f0ac-f265-5d38-b1ab-50d9e4ce67e5

STIX ID: report--5a51f0ac-f265-5d38-b1ab-50d9e4ce67e5

Feed Name: Zscaler Security Research Blog

Threat Score
45/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A Zscaler researcher describes repeatedly finding legitimate websites that intentionally accept JavaScript and full SQL/HTML in URL parameters—resulting in XSS-by-design, SQL-query exposure, and unsafe include patterns. The post highlights widespread insecure coding practices that could enable XSS or SQL injection exploitation, though the author did not perform active tests and reports no confirmed exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.