Property
Languageregex
Severitylow
CWECWE-798: Use of Hard-coded Credentials
OWASPA07:2021 - Identification and Authentication Failures
Confidence LevelLow
Impact LevelMedium
Likelihood LevelLow

Description#

A GoCardless API token was found hard-coded in the source code. Storing sensitive credentials directly in code can expose them if the code is shared or leaked.

Impact#

If an attacker gains access to the exposed API token, they could perform unauthorized actions on your GoCardless account, such as initiating or modifying payments, leading to financial loss or data breaches.