ZAP Scanning Report

ZAP Scanning Report

Site: https://app.4shar3.pro

Generated on Fri, 6 Feb 2026 15:18:32

ZAP Version: 2.17.0

ZAP by Checkmarx

Summary of Alerts

Risk Level Number of Alerts
High
0
Medium
5
Low
3
Informational
4
False Positives:
0

Insights

Level Reason Site Description Statistic
Info
Informational
http://app.4shar3.pro
Percentage of responses with status code 3xx
100 %
Info
Informational
https://app.4shar3.pro
Percentage of responses with status code 2xx
58 %
Info
Informational
https://app.4shar3.pro
Percentage of responses with status code 3xx
25 %
Info
Informational
https://app.4shar3.pro
Percentage of responses with status code 4xx
15 %
Info
Informational
https://app.4shar3.pro
Percentage of endpoints with content type application/json
11 %
Info
Informational
https://app.4shar3.pro
Percentage of endpoints with content type image/png
22 %
Info
Informational
https://app.4shar3.pro
Percentage of endpoints with content type text/html
55 %
Info
Informational
https://app.4shar3.pro
Percentage of endpoints with content type text/javascript
11 %
Info
Informational
https://app.4shar3.pro
Percentage of endpoints with method GET
100 %
Info
Informational
https://app.4shar3.pro
Count of total endpoints
9
Info
Informational
https://app.4shar3.pro
Percentage of slow responses
8 %
Info
Informational
https://cdn.jsdelivr.net
Percentage of responses with status code 2xx
100 %
Info
Informational
https://cdn.jsdelivr.net
Percentage of slow responses
50 %

Summary of Sequences

For each step: result (Pass/Fail) - risk (of highest alert(s) for the step, if any).

Alerts

Name Risk Level Number of Instances
CSP: Wildcard Directive Medium 1
CSP: script-src unsafe-inline Medium 1
CSP: style-src unsafe-inline Medium 1
Content Security Policy (CSP) Header Not Set Medium 1
Sub Resource Integrity Attribute Missing Medium 1
Cross-Domain JavaScript Source File Inclusion Low 1
Strict-Transport-Security Header Not Set Low Systemic
X-Content-Type-Options Header Missing Low 5
Information Disclosure - Suspicious Comments Informational 2
Modern Web Application Informational 1
Re-examine Cache-control Directives Informational 2
User Agent Fuzzer Informational Systemic

Alert Detail

Medium
CSP: Wildcard Directive
Description
Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter Content-Security-Policy
Attack
Evidence default-src 'self' https://www.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com; script-src 'self' 'wasm-unsafe-eval' 'unsafe-inline' https://www.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; font-src 'self' https://fonts.gstatic.com https://www.gstatic.com data:; img-src 'self' data: https: https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com; media-src 'self' https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com; connect-src 'self' https: https://www.gstatic.com https://fonts.gstatic.com https://api.4shar3.pro https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com https://me.kis.v2.scr.kaspersky-labs.com https://one.one.one.one https://icanhazip.com https://jsonplaceholder.typicode.com https://pokeapi.co wss://me.kis.v2.scr.kaspersky-labs.com wss://app.4shar3.pro; worker-src 'self' blob: https://www.gstatic.com; child-src 'self' blob:; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests;
Other Info The following directives either allow wildcard sources (or ancestors), are not defined, or are overly broadly defined: img-src, connect-src
Instances 1
Solution
Ensure that your web server, application server, load balancer, etc. is properly configured to set the Content-Security-Policy header.
Reference https://www.w3.org/TR/CSP/
https://caniuse.com/#search=content+security+policy
https://content-security-policy.com/
https://github.com/HtmlUnit/htmlunit-csp
https://web.dev/articles/csp#resource-options
CWE Id 693
WASC Id 15
Plugin Id 10055
Medium
CSP: script-src unsafe-inline
Description
Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter Content-Security-Policy
Attack
Evidence default-src 'self' https://www.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com; script-src 'self' 'wasm-unsafe-eval' 'unsafe-inline' https://www.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; font-src 'self' https://fonts.gstatic.com https://www.gstatic.com data:; img-src 'self' data: https: https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com; media-src 'self' https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com; connect-src 'self' https: https://www.gstatic.com https://fonts.gstatic.com https://api.4shar3.pro https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com https://me.kis.v2.scr.kaspersky-labs.com https://one.one.one.one https://icanhazip.com https://jsonplaceholder.typicode.com https://pokeapi.co wss://me.kis.v2.scr.kaspersky-labs.com wss://app.4shar3.pro; worker-src 'self' blob: https://www.gstatic.com; child-src 'self' blob:; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests;
Other Info script-src includes unsafe-inline.
Instances 1
Solution
Ensure that your web server, application server, load balancer, etc. is properly configured to set the Content-Security-Policy header.
Reference https://www.w3.org/TR/CSP/
https://caniuse.com/#search=content+security+policy
https://content-security-policy.com/
https://github.com/HtmlUnit/htmlunit-csp
https://web.dev/articles/csp#resource-options
CWE Id 693
WASC Id 15
Plugin Id 10055
Medium
CSP: style-src unsafe-inline
Description
Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks. Including (but not limited to) Cross Site Scripting (XSS), and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter Content-Security-Policy
Attack
Evidence default-src 'self' https://www.gstatic.com https://fonts.googleapis.com https://fonts.gstatic.com; script-src 'self' 'wasm-unsafe-eval' 'unsafe-inline' https://www.gstatic.com https://cdn.jsdelivr.net https://cdnjs.cloudflare.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://www.gstatic.com; font-src 'self' https://fonts.gstatic.com https://www.gstatic.com data:; img-src 'self' data: https: https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com; media-src 'self' https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com; connect-src 'self' https: https://www.gstatic.com https://fonts.gstatic.com https://api.4shar3.pro https://i4-repository-prod.s3.eu-west-1.amazonaws.com https://p4ndor4-application-prod.s3.eu-central-1.amazonaws.com https://me.kis.v2.scr.kaspersky-labs.com https://one.one.one.one https://icanhazip.com https://jsonplaceholder.typicode.com https://pokeapi.co wss://me.kis.v2.scr.kaspersky-labs.com wss://app.4shar3.pro; worker-src 'self' blob: https://www.gstatic.com; child-src 'self' blob:; frame-ancestors 'self'; base-uri 'self'; form-action 'self'; object-src 'none'; upgrade-insecure-requests;
Other Info style-src includes unsafe-inline.
Instances 1
Solution
Ensure that your web server, application server, load balancer, etc. is properly configured to set the Content-Security-Policy header.
Reference https://www.w3.org/TR/CSP/
https://caniuse.com/#search=content+security+policy
https://content-security-policy.com/
https://github.com/HtmlUnit/htmlunit-csp
https://web.dev/articles/csp#resource-options
CWE Id 693
WASC Id 15
Plugin Id 10055
Medium
Content Security Policy (CSP) Header Not Set
Description
Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware. CSP provides a set of standard HTTP headers that allow website owners to declare approved sources of content that browsers should be allowed to load on that page — covered types are JavaScript, CSS, HTML frames, fonts, images and embeddable objects such as Java applets, ActiveX, audio and video files.
URL https://app.4shar3.pro/sitemap.xml
Node Name https://app.4shar3.pro/sitemap.xml
Method GET
Parameter
Attack
Evidence
Other Info
Instances 1
Solution
Ensure that your web server, application server, load balancer, etc. is configured to set the Content-Security-Policy header.
Reference https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP
https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html
https://www.w3.org/TR/CSP/
https://w3c.github.io/webappsec-csp/
https://web.dev/articles/csp
https://caniuse.com/#feat=contentsecuritypolicy
https://content-security-policy.com/
CWE Id 693
WASC Id 15
Plugin Id 10038
Medium
Sub Resource Integrity Attribute Missing
Description
The integrity attribute is missing on a script or link tag served by an external server. The integrity tag prevents an attacker who have gained access to this server from injecting a malicious content.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter
Attack
Evidence <script src='https://cdn.jsdelivr.net/npm/pdfjs-dist@4.6.82/build/pdf.min.mjs' type='module'></script>
Other Info
Instances 1
Solution
Provide a valid integrity attribute to the tag.
Reference https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity
CWE Id 345
WASC Id 15
Plugin Id 90003
Low
Cross-Domain JavaScript Source File Inclusion
Description
The page includes one or more script files from a third-party domain.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter https://cdn.jsdelivr.net/npm/pdfjs-dist@4.6.82/build/pdf.min.mjs
Attack
Evidence <script src='https://cdn.jsdelivr.net/npm/pdfjs-dist@4.6.82/build/pdf.min.mjs' type='module'></script>
Other Info
Instances 1
Solution
Ensure JavaScript source files are loaded from only trusted sources, and the sources can't be controlled by end users of the application.
Reference
CWE Id 829
WASC Id 15
Plugin Id 10017
Low
Strict-Transport-Security Header Not Set
Description
HTTP Strict Transport Security (HSTS) is a web security policy mechanism whereby a web server declares that complying user agents (such as a web browser) are to interact with it using only secure HTTPS connections (i.e. HTTP layered over TLS/SSL). HSTS is an IETF standards track protocol and is specified in RFC 6797.
URL https://app.4shar3.pro/newapp/favicon.png
Node Name https://app.4shar3.pro/newapp/favicon.png
Method GET
Parameter
Attack
Evidence
Other Info
URL https://app.4shar3.pro/newapp/flutter_bootstrap.js
Node Name https://app.4shar3.pro/newapp/flutter_bootstrap.js
Method GET
Parameter
Attack
Evidence
Other Info
URL https://app.4shar3.pro/newapp/icons/Icon-192.png
Node Name https://app.4shar3.pro/newapp/icons/Icon-192.png
Method GET
Parameter
Attack
Evidence
Other Info
URL https://app.4shar3.pro/robots.txt
Node Name https://app.4shar3.pro/robots.txt
Method GET
Parameter
Attack
Evidence
Other Info
URL https://app.4shar3.pro/sitemap.xml
Node Name https://app.4shar3.pro/sitemap.xml
Method GET
Parameter
Attack
Evidence
Other Info
Instances Systemic
Solution
Ensure that your web server, application server, load balancer, etc. is configured to enforce Strict-Transport-Security.
Reference https://cheatsheetseries.owasp.org/cheatsheets/HTTP_Strict_Transport_Security_Cheat_Sheet.html
https://owasp.org/www-community/Security_Headers
https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
https://caniuse.com/stricttransportsecurity
https://datatracker.ietf.org/doc/html/rfc6797
CWE Id 319
WASC Id 15
Plugin Id 10035
Low
X-Content-Type-Options Header Missing
Description
The Anti-MIME-Sniffing header X-Content-Type-Options was not set to 'nosniff'. This allows older versions of Internet Explorer and Chrome to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other than the declared content type. Current (early 2014) and legacy versions of Firefox will use the declared content type (if one is set), rather than performing MIME-sniffing.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter x-content-type-options
Attack
Evidence
Other Info This issue still applies to error type pages (401, 403, 500, etc.) as those pages are often still affected by injection issues, in which case there is still concern for browsers sniffing pages away from their actual content type. At "High" threshold this scan rule will not alert on client or server error responses.
URL https://app.4shar3.pro/newapp/favicon.png
Node Name https://app.4shar3.pro/newapp/favicon.png
Method GET
Parameter x-content-type-options
Attack
Evidence
Other Info This issue still applies to error type pages (401, 403, 500, etc.) as those pages are often still affected by injection issues, in which case there is still concern for browsers sniffing pages away from their actual content type. At "High" threshold this scan rule will not alert on client or server error responses.
URL https://app.4shar3.pro/newapp/flutter_bootstrap.js
Node Name https://app.4shar3.pro/newapp/flutter_bootstrap.js
Method GET
Parameter x-content-type-options
Attack
Evidence
Other Info This issue still applies to error type pages (401, 403, 500, etc.) as those pages are often still affected by injection issues, in which case there is still concern for browsers sniffing pages away from their actual content type. At "High" threshold this scan rule will not alert on client or server error responses.
URL https://app.4shar3.pro/newapp/icons/Icon-192.png
Node Name https://app.4shar3.pro/newapp/icons/Icon-192.png
Method GET
Parameter x-content-type-options
Attack
Evidence
Other Info This issue still applies to error type pages (401, 403, 500, etc.) as those pages are often still affected by injection issues, in which case there is still concern for browsers sniffing pages away from their actual content type. At "High" threshold this scan rule will not alert on client or server error responses.
URL https://app.4shar3.pro/newapp/manifest.json
Node Name https://app.4shar3.pro/newapp/manifest.json
Method GET
Parameter x-content-type-options
Attack
Evidence
Other Info This issue still applies to error type pages (401, 403, 500, etc.) as those pages are often still affected by injection issues, in which case there is still concern for browsers sniffing pages away from their actual content type. At "High" threshold this scan rule will not alert on client or server error responses.
Instances 5
Solution
Ensure that the application/web server sets the Content-Type header appropriately, and that it sets the X-Content-Type-Options header to 'nosniff' for all web pages.

If possible, ensure that the end user uses a standards-compliant and modern web browser that does not perform MIME-sniffing at all, or that can be directed by the web application/web server to not perform MIME-sniffing.
Reference https://learn.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-developer/compatibility/gg622941(v=vs.85)
https://owasp.org/www-community/Security_Headers
CWE Id 693
WASC Id 15
Plugin Id 10021
Informational
Information Disclosure - Suspicious Comments
Description
The response appears to contain suspicious comments which may help an attacker.
URL https://app.4shar3.pro/newapp/flutter_bootstrap.js
Node Name https://app.4shar3.pro/newapp/flutter_bootstrap.js
Method GET
Parameter
Attack
Evidence debug
Other Info The following pattern was used: \bDEBUG\b and was detected in likely comment: "//www.gstatic.com/flutter-canvaskit",e.engineRevision):"canvaskit"}var h=class{constructor(){this._scriptLoaded=!1}setTrustedTyp", see evidence field for the suspicious comment/snippet.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter
Attack
Evidence from
Other Info The following pattern was used: \bFROM\b and was detected in likely comment: "<!-- If you are serving your web app in a path other than the root, change the href value below to reflect the base pa", see evidence field for the suspicious comment/snippet.
Instances 2
Solution
Remove all comments that return information that may help an attacker and fix any underlying problems they refer to.
Reference
CWE Id 615
WASC Id 13
Plugin Id 10027
Informational
Modern Web Application
Description
The application appears to be a modern web application. If you need to explore it automatically then the Ajax Spider may well be more effective than the standard one.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter
Attack
Evidence <script src='https://cdn.jsdelivr.net/npm/pdfjs-dist@4.6.82/build/pdf.min.mjs' type='module'></script>
Other Info No links have been found while there are scripts, which is an indication that this is a modern web application.
Instances 1
Solution
This is an informational alert and so no changes are required.
Reference
CWE Id
WASC Id
Plugin Id 10109
Informational
Re-examine Cache-control Directives
Description
The cache-control header has not been set properly or is missing, allowing the browser and proxies to cache content. For static assets like css, js, or image files this might be intended, however, the resources should be reviewed to ensure that no sensitive content will be cached.
URL https://app.4shar3.pro/newapp/
Node Name https://app.4shar3.pro/newapp/
Method GET
Parameter cache-control
Attack
Evidence
Other Info
URL https://app.4shar3.pro/newapp/manifest.json
Node Name https://app.4shar3.pro/newapp/manifest.json
Method GET
Parameter cache-control
Attack
Evidence
Other Info
Instances 2
Solution
For secure content, ensure the cache-control HTTP header is set with "no-cache, no-store, must-revalidate". If an asset should be cached consider setting the directives "public, max-age, immutable".
Reference https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.html#web-content-caching
https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Cache-Control
https://grayduck.mn/2021/09/13/cache-control-recommendations/
CWE Id 525
WASC Id 13
Plugin Id 10015
Informational
User Agent Fuzzer
Description
Check for differences in response based on fuzzed User Agent (eg. mobile sites, access as a Search Engine Crawler). Compares the response statuscode and the hashcode of the response body with the original response.
URL https://app.4shar3.pro/newapp
Node Name https://app.4shar3.pro/newapp
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Evidence
Other Info
URL https://app.4shar3.pro/newapp
Node Name https://app.4shar3.pro/newapp
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Other Info
URL https://app.4shar3.pro/newapp
Node Name https://app.4shar3.pro/newapp
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Other Info
URL https://app.4shar3.pro/newapp/icons
Node Name https://app.4shar3.pro/newapp/icons
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Evidence
Other Info
URL https://app.4shar3.pro/newapp/icons
Node Name https://app.4shar3.pro/newapp/icons
Method GET
Parameter Header User-Agent
Attack Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1)
Evidence
Other Info
Instances Systemic
Solution
Reference https://owasp.org/wstg
CWE Id
WASC Id
Plugin Id 10104

Sequence Details

With the associated active scan results.