Property
Languageregex
Severitylow
CWECWE-798: Use of Hard-coded Credentials
OWASPA07:2021 - Identification and Authentication Failures
Confidence LevelLow
Impact LevelMedium
Likelihood LevelLow

Description#

A Picatic API key has been found directly in the codebase. Storing API keys in source code exposes them to anyone with code access, increasing the risk of unauthorized use.

Impact#

If attackers obtain this API key, they could access or manipulate your Picatic account, potentially leading to data breaches, financial loss, or abuse of your organization’s event management services.