Skip to main content

V12.5 — File Download

File Download: 2 L3 requirement(s). V12.5.1: Verify that the web tier is configured to serve only files with specific file extensions to prevent unintentional inform... V12.5.2: Verify that direct requests to uploaded files will never be executed as HTML/JavaScript content.

PropertyValue
SectionV12.5
Ownerplatform

Mapped Controls

ControlTitle
SID-HARD-07Resource Upload Constraints

Source: OWASP Application Security Verification Standard 4.0.3