Project Name: Travel Management System
Secure Software Development (SE4030) | 4th year 1st semester | SLIIT
Backend- https://github.com/Kavinduweb/Travel-management-system
Frontend- https://github.com/Kavinduweb/Travel-management-Frontend
Link- https://github.com/malindu-MD/ssd_assignment_SE4030- Security Misconfiguration (Clickjacking)
- Broken Authentication & Exposing user sensitive information
- Weak Cross-Origin Resource Sharing (CORS) Configurations
- Stored XSS Vulnerability
- File Upload Vulnerability
- Lack of Request Size Limit function
- Missing Content Policy(CSP) Header
- Insecure Direct Object References (IDOR)
- Lack of Rate Limit Function
- Lack of Rate Limit Function
- Weak Password Policies
- Authentication Vulnerability
- Inadequate Logging mechanism
- Snyk
- Zap Tool
- Ranaweera A.P. - IT21182396 (Group Leader)
- Senanayake W.G.B. - IT21158322
- Sooriyaarachchi M.D.A - IT21173790
- Kumarathunga S.A.D.S - IT21118340