OWASP Top 10:2021 - The Ten Most Critical Web Application Security Risks¶
Open Web Application Security Project. (2021). OWASP Top 10:2021 - The Ten Most Critical Web Application Security Risks.
Cited by¶
2 citations across 2 artifacts.
Domain-specific¶
- Authentication Failure
- The canonical exploitation paths in the current landscape are credential theft and stuffing (exploiting password reuse across services), weak or phishable second factors (SMS one-time passwords intercepted via SIM swap), account-recovery flows that apply lower verification standards than the primary login path, token forgery (forged JWTs via algorithm-confusion vulnerabilities or key disclosure), and session hijacking (acquiring a valid session token and bypassing front-door authentication entirely)
Supported in partVerified against a saved copy of the source
“Permits automated attacks such as credential stuffing, where the attacker has a list of valid usernames and passwords.”
- The canonical exploitation paths in the current landscape are credential theft and stuffing (exploiting password reuse across services), weak or phishable second factors (SMS one-time passwords intercepted via SIM swap), account-recovery flows that apply lower verification standards than the primary login path, token forgery (forged JWTs via algorithm-confusion vulnerabilities or key disclosure), and session hijacking (acquiring a valid session token and bypassing front-door authentication entirely)
- Injection Weakness
- SQL injection — the canonical instance and a perennial OWASP Top 10 entry
Supported in partVerified against the source
- SQL injection — the canonical instance and a perennial OWASP Top 10 entry
Verification¶
Does it exist? Not checked yet. This entry carries no identifier to resolve. It was extracted from the citation as written in the article, normalized, and deduplicated against the rest of the registry.
Does it back the claim? Read against the text for 2 of 2 citations: 2 supported in part. Each verdict is shown under its citation below, with what in the work backs the sentence.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:3e6b5dacfff7 · see in the full table