A library admin UI ships a years-outdated JavaScript library known for client-side vulnerability classes. What should the tester emphasize?
Select an answer to reveal the explanation.
Short Explanation
Driving a car with decade-old airbags is a maintenance problem with security teeth. Ancient admin JS libraries can open client-side vuln classes — track them and patch. HTTPS on the API does not retire old browser code, and this is not an AD Domain Admin cheat code.
Full Explanation
Outdated JavaScript dependencies on administrative interfaces can introduce known client-side vulnerability classes, including issues that assist XSS or prototype-pollution themes depending on the library. Testers should inventory versions, cite maintenance risk at awareness depth, and avoid turning the finding into unrelated AD privilege claims. Transport encryption does not remediate vulnerable client code. Recommend patching or replacing stale libraries and reducing unnecessary admin UI scripts.