Property
Languagepython
Severitylow
CWECWE-319: Cleartext Transmission of Sensitive Information
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelMedium
Impact LevelLow
Likelihood LevelLow

Description#

The code is making HTTP requests using ‘http://’ instead of ‘https://’. This means data sent and received is not encrypted, exposing it to anyone monitoring the network.

Impact#

If an attacker intercepts this unencrypted traffic, they could steal sensitive information like login credentials or personal data, or tamper with the communication. This puts users and the application’s security at significant risk.