Skip to content

synk issues for Cross-site Scripting (XSS) #32

Description

@MdMumtajTR

Hi Team,
While running a vulnerability scan using the Snyk tool, I encountered a Cross-site Scripting (XSS) issue related to unsensitized input in the [url] and the issue appears at lines no 1912.(https://github.com/dapphp/radius/blob/master/src/Radius.php) file.

The description of the issue Unsensitized input from an HTTP header flow into the echo statement, where it is used to render an HTML page returned to the user.
This may result in a Cross-Site Scripting attack (XSS).

Currently, I am using dapphp/radius version 3.0

Image

Can anyone provide suggestions to fix the XSS issue?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions