User Controllable JavaScript Event (XSS)

Type: Passive Scan

Description

This check looks at user-supplied input in query string parameters and POST data to identify where certain HTML attribute values might be controlled. This provides hot-spot detection for XSS (cross-site scripting) that will require further review by a security analyst to determine exploitability.

Solution

Validate all input and sanitize output it before writing to any Javascript on* events.

References

Code

Last updated: 2020-04-30 16:12:39.623Z