owasp-zap-jwt-addon icon indicating copy to clipboard operation
owasp-zap-jwt-addon copied to clipboard

Adding Header Param Injection attacks

Open preetkaran20 opened this issue 1 year ago • 0 comments

Is your feature request related to a problem? Please describe. The scan rules present at https://github.com/SasanLabs/owasp-zap-jwt-addon/tree/master/src/main/java/org/zaproxy/zap/extension/jwt/attacks are not having header param injections mentioned at https://portswigger.net/web-security/jwt. There are few other attacks which may not be present in AttackVectors.

Describe the solution you'd like Add the Attack vectors for the left over injections as described at https://portswigger.net/web-security/jwt

preetkaran20 avatar Oct 01 '22 14:10 preetkaran20