A3: Sensitive Data Exposure

Many web applications and APIs do not properly protect sensitive data, such as financial, healthcare, and PII. Attackers may steal or modify such weakly protected data to conduct credit card fraud, identity theft, or other crimes. Sensitive data may be compromised without extra protection, such as encryption at rest or in transit, and requires special precautions when exchanged with the browser.

Our SSTI Example also covers A3 as it opens up a way for attackers to expose sensitive data

This page also has a potential vulnerability within its codebase. Refer to the SAST Tool to find out.