Unsanitized user input in dynamic HTML insertion (XSS)
Overview
Description
Remediation Guidelines
import sanitizeHtml from 'sanitize-html'; const html = `<strong>${user.Input}</strong>`; document.body.innerHTML = sanitizeHtml(html);
References
Configuration
PreviousUnsanitized user input in deserialization methodNextUnsanitized user input in DynamoDB query
Last updated