Unsanitized User Input in UI
Overview
Description
Remediation Guidelines
res.set('X-Frame-Options', 'DENY'); res.set('Content-Security-Policy', "frame-ancestors 'none'");const frameOptions = ['deny', 'sameorigin']; if (frameOptions.includes(req.query.options.toLowerCase())) { res.set('X-Frame-Options', req.query.options.toUpperCase()); }
References
Configuration
Last updated