Skip to content

Suggestion: Another XSS vector #461

Open
@wh1t3h47

Description

I was reading the documentation provided here and I noted that there was something missing in the XSS prevention documentation: Template strings.

As noted here, template strings can introduce an XSS vector in Django, it also might be a good ideia to add a static code analysis rule for that, but I'm not sure if Semgrep already has this rule implemented.

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions