Skip to content
This repository was archived by the owner on Dec 20, 2024. It is now read-only.

remove id from the error message#377

Open
inkz wants to merge 1 commit into
fzaninotto:masterfrom
inkz:patch-1
Open

remove id from the error message#377
inkz wants to merge 1 commit into
fzaninotto:masterfrom
inkz:patch-1

Conversation

@inkz

@inkz inkz commented Dec 19, 2024

Copy link
Copy Markdown

res.send() is sending a string value as an HTML content by default, that is why reflecting the user provided id without any sanitization can be vulnerable to XSS.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant