# Common NightVision Findings and Remediations

Quick reference for vulnerability types commonly reported by NightVision's ZAP and Nuclei engines. For each: what it is, why it matters, and how to fix it.

## High Severity

### SQL Injection (CWE-89)
**What:** User input is interpolated into SQL queries without parameterization.
**Impact:** Full database read/write, data exfiltration, authentication bypass.
**Fix:** Use parameterized queries or prepared statements. ORMs with bound parameters are safe by default. Never concatenate user input into SQL strings.
```python
# Bad
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")

# Good
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))
```

### Cross-Site Scripting — Reflected (CWE-79)
**What:** User input is echoed back in the HTML response without encoding.
**Impact:** Session hijacking, credential theft, defacement via injected scripts.
**Fix:** HTML-encode all user input rendered in responses. Use framework auto-escaping (enabled by default in most modern frameworks). For JavaScript contexts, use JavaScript-specific escaping.

### Cross-Site Scripting — Stored (CWE-79)
**What:** User input is saved to the database and later rendered to other users without encoding.
**Impact:** Same as reflected XSS but affects all users who view the stored content.
**Fix:** Encode on output, not on input. Sanitize HTML if rich text is needed (use a library like DOMPurify or Bleach).

### Remote Code Execution (CWE-94)
**What:** User input reaches a code execution function (eval, exec, system, Runtime.exec).
**Impact:** Full server compromise.
**Fix:** Never pass user input to code execution functions. Use allowlists for permitted operations. Sandbox execution environments if dynamic evaluation is unavoidable.

### Server-Side Template Injection / SSTI (CWE-1336)
**What:** User input is embedded in a server-side template and evaluated.
**Impact:** Remote code execution via template engine.
**Fix:** Never pass user input as template source. Use templates with auto-escaping. Pass user input only as template variables.

### Log4Shell (CVE-2021-44228)
**What:** Log4j JNDI lookup injection via user-controlled log messages.
**Impact:** Remote code execution.
**Fix:** Upgrade Log4j to 2.17.1+. Set `log4j2.formatMsgNoLookups=true`. Remove JndiLookup class from classpath.

### Server-Side Request Forgery / SSRF (CWE-918)
**What:** User input controls a URL that the server fetches.
**Impact:** Access to internal services, cloud metadata endpoints, port scanning.
**Fix:** Validate and allowlist target URLs/domains. Block private/internal IP ranges (10.x, 172.16.x, 192.168.x, 169.254.x). Don't follow redirects blindly.

### Path Traversal (CWE-22)
**What:** User input manipulates file paths to access files outside the intended directory.
**Impact:** Read sensitive files (config, credentials, source code).
**Fix:** Canonicalize paths and verify they remain within the intended root directory. Use chroot or built-in framework path resolution.

### JWT Vulnerabilities
**What:** JWT signature validation bypassed (alg:none, weak keys, key confusion).
**Impact:** Authentication bypass, privilege escalation.
**Fix:** Always validate JWT signatures. Reject `alg: none`. Use strong, asymmetric keys. Validate issuer and audience claims.

### Open Redirect (CWE-601)
**What:** User input controls a redirect target URL.
**Impact:** Phishing attacks using the application's trusted domain.
**Fix:** Validate redirect URLs against an allowlist of permitted domains. Use relative paths only.

## Medium Severity

### Missing Anti-CSRF Token (CWE-352)
**What:** State-changing forms lack CSRF protection tokens.
**Impact:** Attackers can forge requests on behalf of authenticated users.
**Fix:** Use framework CSRF middleware (Django CSRF, Spring CSRF, Express csurf). Include tokens in all state-changing forms.

### Missing Security Headers
**What:** Response lacks headers like Content-Security-Policy, X-Content-Type-Options, Strict-Transport-Security.
**Impact:** Browser-side protections not activated, increasing attack surface.
**Fix:** Add security headers via middleware or web server config:
```
Content-Security-Policy: default-src 'self'
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Frame-Options: DENY
```

### Insecure Cookie Configuration
**What:** Session cookies lack Secure, HttpOnly, or SameSite flags.
**Impact:** Cookie theft via XSS or network interception.
**Fix:** Set all session cookies with `Secure; HttpOnly; SameSite=Lax` (or `Strict`).

### Directory Browsing (CWE-548)
**What:** Web server lists directory contents when no index file exists.
**Impact:** Information disclosure — reveals file structure, backup files, hidden endpoints.
**Fix:** Disable directory listing in web server configuration.

### HTTP-Only Site (CWE-311)
**What:** Application served over HTTP without TLS.
**Impact:** All traffic including credentials transmitted in plaintext.
**Fix:** Enable HTTPS. Redirect all HTTP to HTTPS. Set HSTS header.

## Low / Informational

### Information Disclosure in Error Messages
**What:** Stack traces, debug info, or internal paths leaked in error responses.
**Fix:** Use generic error pages in production. Log details server-side only.

### Server Version Disclosure
**What:** Server header reveals software version (e.g., `Apache/2.4.49`).
**Fix:** Suppress version information in server headers.

### Application Error Disclosure
**What:** Application returns verbose error details to the client.
**Fix:** Catch exceptions and return generic error responses. Log full details server-side.
