Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update cxaction.yml #164

Open
wants to merge 24 commits into
base: actiontest
Choose a base branch
from
Open

Update cxaction.yml #164

wants to merge 24 commits into from

Conversation

apcxtest
Copy link
Owner

@apcxtest apcxtest commented Aug 5, 2024

No description provided.

@apcxtest apcxtest closed this Sep 13, 2024
@apcxtest apcxtest reopened this Sep 13, 2024
Copy link

github-actions bot commented Jan 15, 2025

Logo
Checkmarx One – Scan Summary & Detailsf04e0735-3a23-4230-b1ca-971fe5982a0f

New Issues (115)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
CRITICAL SQL_Injection /OrdersGrid.cs: 229
detailsThe application's Orders_CreateDataSource method executes an SQL query with Fill, at line 304 of /OrdersGrid.cs. The application constructs this SQ...
Attack Vector
CRITICAL SQL_Injection /MembersGrid.cs: 219
detailsThe application's Members_CreateDataSource method executes an SQL query with Fill, at line 287 of /MembersGrid.cs. The application constructs this ...
Attack Vector
CRITICAL SQL_Injection /MembersGrid.cs: 219
detailsThe application's Members_CreateDataSource method executes an SQL query with Fill, at line 287 of /MembersGrid.cs. The application constructs this ...
Attack Vector
CRITICAL SQL_Injection /MembersInfo.cs: 311
detailsThe application's Orders_CreateDataSource method executes an SQL query with Fill, at line 371 of /MembersInfo.cs. The application constructs this S...
Attack Vector
CRITICAL SQL_Injection /ShoppingCartRecord.cs: 164
detailsThe application's ShoppingCartRecord_Show method executes an SQL query with Fill, at line 173 of /ShoppingCartRecord.cs. The application constructs...
Attack Vector
CRITICAL SQL_Injection /OrdersGrid.cs: 229
detailsThe application's Orders_CreateDataSource method executes an SQL query with Fill, at line 304 of /OrdersGrid.cs. The application constructs this SQ...
Attack Vector
CRITICAL SQL_Injection /CategoriesGrid.cs: 171
detailsThe application's Categories_CreateDataSource method executes an SQL query with Fill, at line 215 of /CategoriesGrid.cs. The application constructs...
Attack Vector
CRITICAL SQL_Injection /CategoriesGrid.cs: 171
detailsThe application's Categories_CreateDataSource method executes an SQL query with Fill, at line 215 of /CategoriesGrid.cs. The application constructs...
Attack Vector
CRITICAL SQL_Injection /CardTypesGrid.cs: 169
detailsThe application's CardTypes_CreateDataSource method executes an SQL query with Fill, at line 204 of /CardTypesGrid.cs. The application constructs t...
Attack Vector
CRITICAL SQL_Injection /CardTypesGrid.cs: 169
detailsThe application's CardTypes_CreateDataSource method executes an SQL query with Fill, at line 204 of /CardTypesGrid.cs. The application constructs t...
Attack Vector
CRITICAL SQL_Injection /MembersRecord.cs: 168
detailsThe application's Members_Show method executes an SQL query with Fill, at line 177 of /MembersRecord.cs. The application constructs this SQL query ...
Attack Vector
CRITICAL SQL_Injection /EditorialsRecord.cs: 167
detailsThe application's editorials_Show method executes an SQL query with Fill, at line 176 of /EditorialsRecord.cs. The application constructs this SQL ...
Attack Vector
CRITICAL SQL_Injection /OrdersRecord.cs: 167
detailsThe application's Orders_Show method executes an SQL query with Fill, at line 176 of /OrdersRecord.cs. The application constructs this SQL query by...
Attack Vector
CRITICAL SQL_Injection /test3folder/BookMaint.cs: 166
detailsThe application's Book_Show method executes an SQL query with Fill, at line 175 of /test3folder/BookMaint.cs. The application constructs this SQL q...
Attack Vector
CRITICAL SQL_Injection /EditorialCatRecord.cs: 165
detailsThe application's editorial_categories_Show method executes an SQL query with Fill, at line 174 of /EditorialCatRecord.cs. The application construc...
Attack Vector
CRITICAL SQL_Injection /CardTypesRecord.cs: 165
detailsThe application's CardTypes_Show method executes an SQL query with Fill, at line 174 of /CardTypesRecord.cs. The application constructs this SQL qu...
Attack Vector
CRITICAL SQL_Injection /CategoriesRecord.cs: 165
detailsThe application's Categories_Show method executes an SQL query with Fill, at line 174 of /CategoriesRecord.cs. The application constructs this SQL ...
Attack Vector
CRITICAL SQL_Injection /MembersInfo.cs: 311
detailsThe application's Orders_CreateDataSource method executes an SQL query with Fill, at line 371 of /MembersInfo.cs. The application constructs this S...
Attack Vector
CRITICAL SQL_Injection /MembersInfo.cs: 173
detailsThe application's Record_Show method executes an SQL query with Fill, at line 182 of /MembersInfo.cs. The application constructs this SQL query by ...
Attack Vector
CRITICAL SQL_Injection /EditorialsGrid.cs: 171
detailsThe application's editorials_CreateDataSource method executes an SQL query with Fill, at line 222 of /EditorialsGrid.cs. The application constructs...
Attack Vector
CRITICAL SQL_Injection /EditorialsGrid.cs: 171
detailsThe application's editorials_CreateDataSource method executes an SQL query with Fill, at line 222 of /EditorialsGrid.cs. The application constructs...
Attack Vector
CRITICAL SQL_Injection /EditorialCatGrid.cs: 171
detailsThe application's editorial_categories_CreateDataSource method executes an SQL query with Fill, at line 215 of /EditorialCatGrid.cs. The applicatio...
Attack Vector
CRITICAL SQL_Injection /EditorialCatGrid.cs: 171
detailsThe application's editorial_categories_CreateDataSource method executes an SQL query with Fill, at line 215 of /EditorialCatGrid.cs. The applicatio...
Attack Vector
CRITICAL SQL_Injection /BookDetail.cs: 314
detailsThe application's Order_Show method executes an SQL query with Fill, at line 323 of /BookDetail.cs. The application constructs this SQL query by em...
Attack Vector
CRITICAL SQL_Injection /BookDetail.cs: 468
detailsThe application's Rating_Show method executes an SQL query with Fill, at line 477 of /BookDetail.cs. The application constructs this SQL query by e...
Attack Vector
CRITICAL SQL_Injection /BookDetail.cs: 179
detailsThe application's Detail_Show method executes an SQL query with Fill, at line 188 of /BookDetail.cs. The application constructs this SQL query by e...
Attack Vector
CRITICAL SQL_Injection /MembersGrid.cs: 219
detailsThe application's Members_CreateDataSource method executes an SQL query with ExecuteScalar, at line 289 of /MembersGrid.cs. The application constru...
Attack Vector
CRITICAL SQL_Injection /MembersGrid.cs: 219
detailsThe application's Members_CreateDataSource method executes an SQL query with ExecuteScalar, at line 289 of /MembersGrid.cs. The application constru...
Attack Vector
CRITICAL SQL_Injection /BookDetail.cs: 579
detailsThe application's Rating_update_Click method executes an SQL query with ExecuteNonQuery, at line 584 of /BookDetail.cs. The application constructs ...
Attack Vector
CRITICAL SQL_Injection /BookDetail.cs: 579
detailsThe application's Rating_update_Click method executes an SQL query with ExecuteNonQuery, at line 584 of /BookDetail.cs. The application constructs ...
Attack Vector
CRITICAL SQL_Injection /OrdersGrid.cs: 229
detailsThe application's Orders_CreateDataSource method executes an SQL query with ExecuteScalar, at line 306 of /OrdersGrid.cs. The application construct...
Attack Vector
CRITICAL SQL_Injection /ShoppingCartRecord.cs: 245
detailsThe application's ShoppingCartRecord_update_Click method executes an SQL query with ExecuteNonQuery, at line 265 of /ShoppingCartRecord.cs. The app...
Attack Vector
CRITICAL SQL_Injection /MyInfo.cs: 262
detailsThe application's Form_update_Click method executes an SQL query with ExecuteNonQuery, at line 289 of /MyInfo.cs. The application constructs this S...
Attack Vector
CRITICAL SQL_Injection /CategoriesRecord.cs: 271
detailsThe application's Categories_update_Click method executes an SQL query with ExecuteNonQuery, at line 290 of /CategoriesRecord.cs. The application c...
Attack Vector
CRITICAL SQL_Injection /CardTypesRecord.cs: 271
detailsThe application's CardTypes_update_Click method executes an SQL query with ExecuteNonQuery, at line 290 of /CardTypesRecord.cs. The application con...
Attack Vector
CRITICAL SQL_Injection /EditorialCatRecord.cs: 271
detailsThe application's editorial_categories_update_Click method executes an SQL query with ExecuteNonQuery, at line 290 of /EditorialCatRecord.cs. The a...
Attack Vector
CRITICAL SQL_Injection /ShoppingCartRecord.cs: 285
detailsThe application's ShoppingCartRecord_delete_Click method executes an SQL query with ExecuteNonQuery, at line 295 of /ShoppingCartRecord.cs. The app...
Attack Vector
CRITICAL SQL_Injection /EditorialsRecord.cs: 299
detailsThe application's editorials_update_Click method executes an SQL query with ExecuteNonQuery, at line 321 of /EditorialsRecord.cs. The application c...
Attack Vector
CRITICAL SQL_Injection /OrdersRecord.cs: 305
detailsThe application's Orders_update_Click method executes an SQL query with ExecuteNonQuery, at line 326 of /OrdersRecord.cs. The application construct...
Attack Vector
CRITICAL SQL_Injection /CategoriesRecord.cs: 310
detailsThe application's Categories_delete_Click method executes an SQL query with ExecuteNonQuery, at line 320 of /CategoriesRecord.cs. The application c...
Attack Vector
CRITICAL SQL_Injection /CardTypesRecord.cs: 310
detailsThe application's CardTypes_delete_Click method executes an SQL query with ExecuteNonQuery, at line 320 of /CardTypesRecord.cs. The application con...
Attack Vector

More results are available on the CxOne platform

Fixed Issues (19)
Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
MEDIUM Missing_HSTS_Header /test1folder/AdminBooks.aspx: 1
LOW Improper_Exception_Handling /test3folder/Books.cs: 531
LOW Improper_Exception_Handling /test3folder/Books.cs: 294
LOW Improper_Exception_Handling /test3folder/BookMaint.cs: 175
LOW Improper_Exception_Handling /test1folder/AdminBooks.cs: 307
LOW Improper_Exception_Handling /test3folder/Books.cs: 296
LOW Improper_Exception_Handling /test1folder/AdminBooks.cs: 309
LOW Improper_Resource_Shutdown_or_Release /test3folder/Books.cs: 295
LOW Improper_Resource_Shutdown_or_Release /test3folder/BookMaint.cs: 282
LOW Improper_Resource_Shutdown_or_Release /test3folder/Books.cs: 291
LOW Improper_Resource_Shutdown_or_Release /test3folder/BookMaint.cs: 171
LOW Improper_Resource_Shutdown_or_Release /test1folder/AdminBooks.cs: 304
LOW Improper_Resource_Shutdown_or_Release /test1folder/AdminBooks.cs: 308
LOW Improper_Resource_Shutdown_or_Release /test3folder/BookMaint.cs: 368
LOW Improper_Resource_Shutdown_or_Release /test3folder/Books.cs: 528
LOW Improper_Resource_Shutdown_or_Release /test3folder/BookMaint.cs: 338
LOW Missing_Content_Security_Policy /test1folder/AdminBooks.aspx: 1
LOW Missing_X_Frame_Options /test1folder/AdminBooks.aspx: 1
LOW Potential_Clickjacking_on_Legacy_Browsers /test1folder/AdminBooks.aspx: 1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant