Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Cross-site scripting (XSS) vulnerabilities occur when untrusted data enters a web application and is sent to a web browser without proper validation or encoding. XSS allows attackers to execute scripts in the victim's browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.
Cómo corregir esta vulnerabilidad
Estrategias de prevención para Cross-Site Scripting (XSS) basadas en 4 reglas de detección de Shoulder.
Validate content with strict allowlists before using DomSanitizer.bypassSecurityTrust methods
import { Pipe, PipeTransform } from '@angular/core'; import { DomSanitizer, SafeHtml } from '@angular/platform-browser'; - - @Pipe({ name: 'safeHtml' }) - export class SafeHtmlPipe implements PipeTransform { - constructor(private sanitizer: DomSanitizer) {} - - transform(value: string): SafeHtml { - return this.sanitizer.bypassSecurityTrustHtml(value); - } - } - - // In template: <div [innerHTML]="userComment | safeHtml"></div> + import DOMPurify from 'dompurify'; + + @Pipe({ name: 'safeHtml' }) + export class SafeHtmlPipe implements PipeTransform { + constructor(private sanitizer: DomSanitizer) {} + + transform(value: string): SafeHtml { + const clean = DOMPurify.sanitize(value, { + ALLOWED_TAGS: ['p', 'br', 'strong', 'em', 'a'], + ALLOWED_ATTR: ['href'], + }); + return this.sanitizer.bypassSecurityTrustHtml(clean); + } + }
Sanitize user content with DOMPurify before binding to innerHTML, or use text interpolation instead
import { Component, Input } from '@angular/core'; - - @Component({ - selector: 'app-comment', - template: ` - <div [innerHTML]="comment.body"></div> - <img [src]="comment.avatarUrl"> - <a [href]="comment.profileLink">Profile</a> - ` - }) - export class CommentComponent { - @Input() comment: any; + import DOMPurify from 'dompurify'; + + @Component({ + selector: 'app-comment', + template: ` + <div [innerHTML]="sanitizedBody"></div> + <img [src]="safeAvatarUrl"> + <a [href]="safeProfileLink">Profile</a> + ` + }) + export class CommentComponent { + @Input() comment: any; + + get sanitizedBody(): string { + return DOMPurify.sanitize(this.comment.body, { + ALLOWED_TAGS: ['p', 'br', 'strong', 'em'], + }); + } + + get safeAvatarUrl(): string { + const url = new URL(this.comment.avatarUrl); + return url.protocol === 'https:' ? url.href : '/default-avatar.png'; + } + + get safeProfileLink(): string { + const url = new URL(this.comment.profileLink); + return url.protocol === 'https:' ? url.href : '#'; + } }
Use HTML encoding or sanitization libraries before output
const http = require('http'); const url = require('url'); - - http.createServer((req, res) => { - const name = url.parse(req.url, true).query.name; - // Vulnerable: user input directly in HTML - res.writeHead(200, { 'Content-Type': 'text/html' }); - res.end(`<h1>Hello ${name}</h1>`); + const he = require('he'); // HTML entity encoder + + http.createServer((req, res) => { + const name = url.parse(req.url, true).query.name; + // Safe: HTML-encode user input + const safeName = he.encode(name || ''); + res.writeHead(200, { 'Content-Type': 'text/html' }); + res.end(`<h1>Hello ${safeName}</h1>`); }).listen(3000);
Use template rendering with auto-escaping or html.escape() for manual escaping
- from flask import request, make_response - - @app.route('/greet') - def greet(): - name = request.args.get('name') - return make_response(f'<h1>Hello {name}</h1>') + import html + from flask import request, render_template + + @app.route('/greet') + def greet(): + name = request.args.get('name') + return render_template('greet.html', name=name)
Encuentra vulnerabilidades en tu código
Usa Shoulder para escanear tu código en busca de patrones Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). 4 reglas.
# Scan with Shoulder CLI npx @shoulderdev/cli trust --cwe=79 # Or scan entire project npx @shoulderdev/cli trust .
Reglas de Detección (4)
Qué buscar en las revisiones de código
Estos patrones indican vulnerabilidades potenciales de Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). Búscalos durante las revisiones de código y auditorías de seguridad.
Escanea tu base de código para Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Shoulder CLI encuentra patrones vulnerables en toda tu base de código.