Property
Languagepython
Severitylow
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

The code is using OpenerDirector.open() to access URLs over ‘http://’ instead of ‘https://’. This means data sent and received is not encrypted and can be intercepted by attackers.

Impact#

Transmitting information over an unencrypted channel exposes sensitive data (like credentials or personal info) to interception or tampering by attackers. This can lead to data breaches, account compromise, and undermines user trust in the application.