Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The script sends user-supplied query parameters and date values over plain HTTP to an internal IP address, so request data can be observed or modified by anyone with network visibility on the path. Because the tool is specifically designed to transmit potentially sensitive macro query inputs and gives no warning that the connection is unencrypted, this is a real confidentiality and integrity risk rather than a cosmetic issue.
