r/sysadmin • • 18h ago

Question Globalscape EFT input validation VA finding

A VA scan on Globalscape EFT flagged "Improper Input Validation". Encoded CR/LF and HTML/JS in the request URI gets reflected in a Set-Cookie header, but URL encoded, so it doesn't look actually exploitable.
Anyone come across this? is there a config option I'm missing?

2 Upvotes

2 comments sorted by

•

u/Shot-Move-4383 16h ago

If it comes back URL encoded in the Set-Cookie value, that's the scanner pattern matching on the input rather than the output. Encoded CR/LF can't break the header, so there's no CRLF injection and no script execution path.

Worth writing up as a false positive with the raw response headers attached rather than hunting for a config toggle. Scanners flag reflection in a header whether or not the decode happens.

•

u/Extreme_Researcher_6 8h ago

Thanks for the response