这是indexloc提供的服务,不要输入任何密码
Skip to content

HTML Report data is not HTML encoded #54

@insideou7

Description

@insideou7

XSS Vulnerability evidence is ironically injected into the HTML report. See example excerpt below:

        <tr>
            <td width="20%">
                <p class="lead font-italic" style="font-size: 1.1em;">&nbsp;&nbsp;&nbsp;&nbsp;Evidence</p>
            </td>
            <td width="80%">
                <p class="lead"></blockquote><script>alert(1);</script><blockquote></p>
            </td>
        </tr>

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions