Skip to content

Input Validation & Sanitisation #5

@emperor42

Description

@emperor42

Several handlers accept arbitrary user input (e.g., filenames in importHandler, query parameters in queryHandler) and embed them directly into HTML without thorough sanitisation. This opens XSS vectors.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Status

Scheduled

Relationships

None yet

Development

No branches or pull requests

Issue actions