Recently we deployed a Blazor application to one of our clients. When their internal team did a WARP test, we got a finding "ClearText transmission of Sensitive Information". When we analyzed it we found that the Blazor heartbeat is sending values typed in every input field to the server via "DispatchBrowserEvent". Given below is a screenshot of the same. DispatchBrowserEvent
I need a solution to either
- Encrypt the value being sent in the DispatchBrowserEvent or
- To Stop the transmission of the values until its manually posted.