ASP.net
Awesome
Learn
Forum
Buy
Demos
Sign In
☾
☀
Switch to
Dark
Light
Mode
this site works best with javascript enabled
Ask Question
Veracode cross-site scripting (XSS) security flaw report for AwesomeMvc.js v4.0
Title:
B
I
{code}
?
Hello, we ran our code thru Veracode static analysis and the awesomemvc.js v4.0 was flagged with cross-site scripting (XSS) flaw. Below are the details Flaw Description This call contains a cross-site scripting (XSS) flaw. The application populates the HTTP response with untrusted input, allowing an attacker to embed malicious content, such as Javascript code, which will be executed in the context of the victim's browser. XSS vulnerabilities are commonly exploited to steal or manipulate cookies, modify presentation of content, and compromise confidential information, with new attack vectors being discovered on a regular basis. Instances found via Static Scan /AwesomeMvc.js Line 7 /AwesomeMvc.js Line 8 /AwesomeMvc.js Line 37 /AwesomeMvc.js Line 42 /AwesomeMvc.js Line 43 /AwesomeMvc.js Line 44 Wondering if these issues have been addressed in the version 5.5? Thanks
Save Changes
Cancel
Shailesh Lahoti
asked at 18 Sep 2018
you can download the latest and try it; is this the original AwesomeMvc.js ? the one we provide for download has all the code in one line can you demonstrate the flaw (perhaps in a mini demo) and confirm it ?
at 18 Sep 2018
Omu
My question is have you ran the Veracode static scan on AwesomeMvc.js? either version.
at 18 Sep 2018
Shailesh Lahoti
no, we are not using the technology you mentioned; we are not using user input to generate the html for our helpers, so think the problems you mention are false
at 18 Sep 2018
Omu
Answers
please
Sign In
to leave an answer
By accessing this site, you agree to store cookies on your device and disclose information in accordance with our
cookie policy
and
privacy policy
.
OK