forked from inno-devops-labs/DevSecOps-Intro
-
Notifications
You must be signed in to change notification settings - Fork 0
Open
Labels
Description
Description:
DOM-based Cross-Site Scripting (XSS) vulnerability in the search functionality. Malicious iframe injection is possible and executes in user's browser.
Solution:
Use Content Security Policy (CSP) headers.
Validate and filter HTML tags from search queries.
Reactions are currently unavailable