Sanitize HTML in HTTP error messages #3453
Labels
enhancement
Enhancement or improvement to existing feature or request
security
Anything security related
Severity-Minor
Describe the bug
Some HTTP error responses include unsanitized user inputs. Since the responses are JSON objects with
content-type: application/json
, this is not a security vulnerability but common security scanners raise a false-positive.To Reproduce
Steps to reproduce the behavior:
curl "https://.../<script>cross_site_scripting.nasl</script>.asp" --verbose
<script>cross_site_scripting.nasl</script>
Expected behavior
%3Cscript%3Ecross_site_scripting.nasl%3C/script%3E
or at the very least,cross_site_scripting.nasl
.Additional context
The text was updated successfully, but these errors were encountered: