You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, I have one project webAR project with artoolkit library. Everything is working fine. But in this project, we need to submit our code to scan thru VAPT (Vulnerability Assessment and Penetration Testing). We completed the scan and found 2 "Improper Neutralization of Input During Web Page Generation ('Crosssite Scripting')" weakness.
We don’t think it’s a real vulnerability, more like a false positive but our security team requires us to get an explanation from the author of the library (ARtoolkit.js) to prove that the vulnerabilities are indeed a false positive.
Can anyone help me with this? I can send more details privately, if more information is needed.
The text was updated successfully, but these errors were encountered:
I’m not quite sure what you are looking for. The artoolkit.js library is an Emscripten compilation of the artoolkit C++ code which you can find just next to the jsartoolkit5 repository.
Hi Thorsten,
I am looking for the author of this library so that we can verify whether the vulnerabilities that was found in the VAPT scan is a real or false vulnerability. I’ve attached the scan report with some picture of the code inside this email. If you are the author or part of the development team, could you take a look and help me verify this?
Thank you for replying. If you need any more details, please let me know. Hope to hear from you soon!
Best Regards,
Sandy
Hi, I have one project webAR project with artoolkit library. Everything is working fine. But in this project, we need to submit our code to scan thru VAPT (Vulnerability Assessment and Penetration Testing). We completed the scan and found 2 "Improper Neutralization of Input During Web Page Generation ('Crosssite Scripting')" weakness.
We don’t think it’s a real vulnerability, more like a false positive but our security team requires us to get an explanation from the author of the library (ARtoolkit.js) to prove that the vulnerabilities are indeed a false positive.
Can anyone help me with this? I can send more details privately, if more information is needed.
The text was updated successfully, but these errors were encountered: