CHECKMARX安全漏洞检测防止XSS跨站脚本攻击
总结CHECKMARX软件安全检测报告高危风险漏洞处理方式
-
高危警告内容
This can enable a Reflected Cross-Site Scripting (XSS) attack -
封装工具类如下
public class ESAPIUtil {
private static ESAPIUtil instance = new ESAPIUtil();
public <T> T encodeForHTML(T t) {
// filter xss
return t;
}
public <T> T canonicalize(T t) {
// filter xss
return t;
}
public <T> T encodeForJavaScript(T t) {
return t;
}
public static ESAPIUtil encoder() {