Skip to content

synk issues for Cross-site Scripting (XSS) #32

@MdMumtajTR

Description

@MdMumtajTR

Hi Team,
While running a vulnerability scan using the Snyk tool, I encountered a Cross-site Scripting (XSS) issue related to unsensitized input in the [url] and the issue appears at lines no 1912.(https://github.com/dapphp/radius/blob/master/src/Radius.php) file.

The description of the issue Unsensitized input from an HTTP header flow into the echo statement, where it is used to render an HTML page returned to the user.
This may result in a Cross-Site Scripting attack (XSS).

Currently, I am using dapphp/radius version 3.0

Image

Can anyone provide suggestions to fix the XSS issue?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions