Info
This section provides information about the test's purpose, the type of vulnerability it targets, the test category and the overall impact. This section contains multiple descriptive keys that explain the test.
Name
The name key shows the name or title
of the test. It should make clear what the test does. The test name helps users quickly identify and understand the purpose of the assessment.
Example:
Description
The description key provides a brief explanation of the test's objective
. This description may contain details about the target system, possible vulnerabilities, and anticipated assessment results.
Example:
Details
In addition to the description section, the details
key provides a more in-depth view. It explains how the API was detected to be vulnerable and also provides information on the test category. The details section may include information about the target system
, potential vulnerabilities
, and the expected outcome of the assessment.
Example:
Impact
The impact
key describes the potential risks
or consequences
associated with the identified vulnerabilities. It helps users understand the severity and potential implications of the vulnerabilities if exploited by attackers.
Example:
Category
This key represents the exact category
to which the test belongs, for example, "Broken User Authentication" or "Broken Object Level Authorization".
Example:
SubCategory
The value of this key is exactly the same as the value of the Id key
.
Example:
Severity
This key is used to assign the severity of the test and can take on values HIGH
, MEDIUM
, or LOW
.
Example:
Tags
The tags
key is used to list relevant categories
or keywords that help users identify the test and understand its purpose.
Example:
References
The references section provides a list of resources
that can be used to obtain additional information about the test. These resources may include websites
, articles
, or other materials.
Example:
Last updated