Details | |
---|---|
Alert ID | 10031 |
Alert Type | Passive |
Status | release |
Risk | Informational |
CWE | 20 |
WASC | 20 |
Technologies Targeted | All |
Tags |
CWE-20 OWASP_2017_A01 OWASP_2021_A03 |
More Info |
Scan Rule Help |
Summary
This check looks at user-supplied input in query string parameters and POST data to identify where certain HTML attribute values might be controlled. This provides hot-spot detection for XSS (cross-site scripting) that will require further review by a security analyst to determine exploitability.