Usage of manual HTML sanitization (XSS)
Overview
Description
Remediation Guidelines
const sanitizedUserInput = user.Input .replaceAll('<', '<') .replaceAll('>', '>'); // unsafe const html = `<strong>${sanitizedUserInput}</strong>`;import sanitizeHtml from 'sanitize-html'; const html = sanitizeHtml(`<strong>${user.Input}</strong>`);
References
Configuration
Last updated