Property
Languageregex
Severitylow
CWECWE-798: Use of Hard-coded Credentials
OWASPA07:2021 - Identification and Authentication Failures
Confidence LevelLow
Impact LevelMedium
Likelihood LevelLow

Description#

A Square OAuth secret key has been found directly in the codebase. Storing sensitive credentials like API secrets in code exposes them to anyone with code access and risks accidental leaks.

Impact#

If an attacker obtains this secret, they could impersonate your application, gain unauthorized access to Square APIs, and potentially access or manipulate sensitive payment data. This could lead to financial loss, service disruptions, or compromise of customer information.