ZAP False Positive for 40018 SQL Injection

50 views
Skip to first unread message

MPR GTR

unread,
May 26, 2025, 5:10:44 AMMay 26
to ZAP Developer Group
Hey,

I have a SQL Injection High Risk but it is false positive so i wanted to know if this works

-z "-alertfilter.addFilter=true -alertfilter.ruleId=40018 -alertfilter.newLevel=FalsePositive -alertfilter.url=.*"

 if this right

psiinon

unread,
May 27, 2025, 6:16:17 AMMay 27
to ZAP Developer Group
No its not.
Did you get that from an LLM? If so you should be aware that LLMs are bad at technical detail :D


But also be aware that for non trivial automation we recommend using the Automation Framework: https://www.zaproxy.org/docs/automate/automation-framework/

Oh, and this group is really for discussions relating to developing ZAP.

For questions about using ZAP please use the User Group next time: https://groups.google.com/group/zaproxy-users

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages