Unsanitized user input in raw HTML strings (XSS)
Overview
Description
Remediation Guidelines
const html = <h1>${req.params.title}</h1> // insecureimport sanitizeHtml from 'sanitize-html' const sanitizedTitle = sanitizeHtml(req.params.title) const html = `<h1>${sanitizedTitle}</h1>`
References
Configuration
Last updated