Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Cross-site scripting (XSS) vulnerabilities occur when untrusted data enters a web application and is sent to a web browser without proper validation or encoding. XSS allows attackers to execute scripts in the victim's browser which can hijack user sessions, deface web sites, or redirect the user to malicious sites.
Como corrigir esta vulnerabilidade
Estratégias de prevenção para Cross-Site Scripting (XSS) baseadas em 4 regras de detecção do Shoulder.
Validate content with strict allowlists before using DomSanitizer.bypassSecurityTrust methods
import { Pipe, PipeTransform } from '@angular/core'; import { DomSanitizer, SafeHtml } from '@angular/platform-browser'; - - @Pipe({ name: 'safeHtml' }) - export class SafeHtmlPipe implements PipeTransform { - constructor(private sanitizer: DomSanitizer) {} - - transform(value: string): SafeHtml { - return this.sanitizer.bypassSecurityTrustHtml(value); - } - } - - // In template: <div [innerHTML]="userComment | safeHtml"></div> + import DOMPurify from 'dompurify'; + + @Pipe({ name: 'safeHtml' }) + export class SafeHtmlPipe implements PipeTransform { + constructor(private sanitizer: DomSanitizer) {} + + transform(value: string): SafeHtml { + const clean = DOMPurify.sanitize(value, { + ALLOWED_TAGS: ['p', 'br', 'strong', 'em', 'a'], + ALLOWED_ATTR: ['href'], + }); + return this.sanitizer.bypassSecurityTrustHtml(clean); + } + }
Sanitize user content with DOMPurify before binding to innerHTML, or use text interpolation instead
import { Component, Input } from '@angular/core'; - - @Component({ - selector: 'app-comment', - template: ` - <div [innerHTML]="comment.body"></div> - <img [src]="comment.avatarUrl"> - <a [href]="comment.profileLink">Profile</a> - ` - }) - export class CommentComponent { - @Input() comment: any; + import DOMPurify from 'dompurify'; + + @Component({ + selector: 'app-comment', + template: ` + <div [innerHTML]="sanitizedBody"></div> + <img [src]="safeAvatarUrl"> + <a [href]="safeProfileLink">Profile</a> + ` + }) + export class CommentComponent { + @Input() comment: any; + + get sanitizedBody(): string { + return DOMPurify.sanitize(this.comment.body, { + ALLOWED_TAGS: ['p', 'br', 'strong', 'em'], + }); + } + + get safeAvatarUrl(): string { + const url = new URL(this.comment.avatarUrl); + return url.protocol === 'https:' ? url.href : '/default-avatar.png'; + } + + get safeProfileLink(): string { + const url = new URL(this.comment.profileLink); + return url.protocol === 'https:' ? url.href : '#'; + } }
Use HTML encoding or sanitization libraries before output
const http = require('http'); const url = require('url'); - - http.createServer((req, res) => { - const name = url.parse(req.url, true).query.name; - // Vulnerable: user input directly in HTML - res.writeHead(200, { 'Content-Type': 'text/html' }); - res.end(`<h1>Hello ${name}</h1>`); + const he = require('he'); // HTML entity encoder + + http.createServer((req, res) => { + const name = url.parse(req.url, true).query.name; + // Safe: HTML-encode user input + const safeName = he.encode(name || ''); + res.writeHead(200, { 'Content-Type': 'text/html' }); + res.end(`<h1>Hello ${safeName}</h1>`); }).listen(3000);
Use template rendering with auto-escaping or html.escape() for manual escaping
- from flask import request, make_response - - @app.route('/greet') - def greet(): - name = request.args.get('name') - return make_response(f'<h1>Hello {name}</h1>') + import html + from flask import request, render_template + + @app.route('/greet') + def greet(): + name = request.args.get('name') + return render_template('greet.html', name=name)
Encontre vulnerabilidades no seu código
Use o Shoulder para escanear seu código em busca de padrões Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). 4 regras.
# Scan with Shoulder CLI npx @shoulderdev/cli trust --cwe=79 # Or scan entire project npx @shoulderdev/cli trust .
Regras de Detecção (4)
O que observar nas revisões de código
Estes padrões indicam vulnerabilidades potenciais de Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). Procure-os durante revisões de código e auditorias de segurança.
Escaneie seu código para Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
O Shoulder CLI encontra padrões vulneráveis em todo o seu código.