Missing User Warnings
Medium
- Confidence
- 97% confidence
- Finding
- Passing an access token in a query parameter is dangerous because query strings are commonly logged by clients, proxies, gateways, browser history, and monitoring tools. Even when sent over HTTPS, the token may be exposed through operational logs or referrer-like propagation, increasing the chance of credential leakage and unauthorized API use.
