Skip to content

Client_DOM_Stored_XSS @ xxe.jsp #96

@mridilla

Description

@mridilla

Client_DOM_Stored_XSS issue exists @ xxe.jsp in branch master

The application's Cx4aa65272 embeds untrusted data in the generated output with html, at line 16 of /src/main/webapp/vulnerability/Injection/xxe.jsp. This untrusted data is embedded straight into the output without proper sanitization or encoding, enabling an attacker to inject malicious code into the output.

Namespace: mridilla
Repository: JavaVulnerableLab
Repository Url: https://github.com/mridilla/JavaVulnerableLab
CxAST-Project: mridilla/JavaVulnerableLab
CxAST platform scan: e1fc43b6-0e4d-4a93-8009-8fe24d4a9091
Branch: master
Application: JavaVulnerableLab
Severity: HIGH
State: TO_VERIFY
Status: RECURRENT
CWE: 79
Lines: 12 15


References
Read more

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions