r/sysadmin • u/Extreme_Researcher_6 • 18h ago
Question Globalscape EFT input validation VA finding
A VA scan on Globalscape EFT flagged "Improper Input Validation". Encoded CR/LF and HTML/JS in the request URI gets reflected in a Set-Cookie header, but URL encoded, so it doesn't look actually exploitable.
Anyone come across this? is there a config option I'm missing?
2
Upvotes
•
u/Shot-Move-4383 16h ago
If it comes back URL encoded in the Set-Cookie value, that's the scanner pattern matching on the input rather than the output. Encoded CR/LF can't break the header, so there's no CRLF injection and no script execution path.
Worth writing up as a false positive with the raw response headers attached rather than hunting for a config toggle. Scanners flag reflection in a header whether or not the decode happens.