In the forthcoming weeks I’ll address the top ten from theĀ Open Web Application Security Project (OWASP) with Intershop Commerce Management from 2013 as the update of 2016 will take a little bit longer. As soon as the update comes out I’ll make an update.
- Injection
- Broken Authentication and Session Management
- Cross-Site Scripting (XSS)
- Insecure Direct Object References
- Security Misconfiguration
- Sensitive Data Exposure
- Missing Function Level Access Control
- Cross-Site Request Forgery (CSRF)
- Using Components with Known Vulnerabilities
- Unvalidated Redirects and Forwards
OWASP Top Ten Project 2013