Skip to content

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

Avoid using custom XSS filtering. Please use standard sanitization functions.

Examples

Insecure Code

scala
class CustomRequestWrapper extends HttpServletRequestWrapper { ... }

Secure Code

scala
use standard sanitization functions like OWASP ESAPI

Remediation

Use standard sanitization functions to prevent cross-site scripting attacks.

Rule Details

FieldValue
IDCODE-0084
CategoryWeb
SeverityMEDIUM
CWECWE-79
ConfidenceHIGH
ImpactMEDIUM
LikelihoodMEDIUM
ExploitabilityEASY
Tagsxss, sanitization
OWASPN/A