Missing User Warnings
Medium
- Confidence
- 96% confidence
- Finding
- Passing an access token as a query parameter is dangerous because query strings are commonly logged by clients, proxies, gateways, browser histories, and monitoring systems. Even when sent over HTTPS, the token may be exposed through operational logging or telemetry, creating a credential leakage risk.
