What is Base64 Disclosure Vulnerability?

Applications may Base64-encode parameters to conceal them from users or to ease the transfer of binary data. The existence of Base64-encoded data might suggest security-sensitive information or functionality that should be investigated further. The data should be examined to see whether it includes any noteworthy information or other entry points for malicious input.

Solution

Manually validating that the Base64 data does not leak sensitive information and that it cannot be aggregated/used to attack other vulnerabilities is the solution for such an issue.

You may use zofixer.com to check your website for the Base64 Disclosure Vulnerability for free.

Leave a Comment

Scroll to Top