Skip to content
This repository was archived by the owner on Dec 20, 2024. It is now read-only.

remove id from the error message #377

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

Conversation

inkz
Copy link

@inkz inkz commented Dec 19, 2024

res.send() is sending a string value as an HTML content by default, that is why reflecting the user provided id without any sanitization can be vulnerable to XSS.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant