• Anthony Fielding (Veracode)

    Hi @SBijavar488612 (Community Member)​,

    Thanks for your question. Unfortunately given the code provided, there isn't enough detail for me to identify why the scanner may have found a CSRF flaw. I recommend scheduling a consultation with a Veracode Application Security Consultant if you would like to discuss the specific finding further. You can find details on how to schedule a consultation here: https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/7YQTCDJKFEQzL3gL_N90hQ.

     

    Thanks,

    Anthony Fielding

    Expand Post
    • Anthony Fielding (Veracode)

      Hello @SBijavar488612 (Community Member)​ ,

      Unfortunately, with .NET for this category of flaws Veracode Static Analysis is not always able to extract enough information from the PDB files to provide accurate line numbers. I recommend taking a look at the Attack Vector in the flaw details and the Data Path to identify the actual method found to contain the flaw. If you still require assistance I still recommend scheduling a consultation as per my initial reply.You may wish to submit an idea to improve the line number resolution here: https://community.veracode.com/s/ideas.

       

      Thanks,

      Anthony Fielding

      Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.