9. of Elevation of Privilege
There’s no reasonable way for callers to figure out what validation of tainted data you perform before passing it to them.
Threat |
|
You’ve not documented what you are and are not validating/sanitizing so others may be making incorrect assumptions that you are handling security on your side, and you are assuming they are securing things on theirs. This leads to neither side securing things properly. |
|
CAPEC |
N/A |
ASVS |
1.1.4 – Verify the system and IO functions have been documented properly |
CWE |
CWE-1111 – Incomplete I/O documentation |
Mitigations |
|
... |