Skip to content

False positive - data: #157

Open
Open
@sevicbb

Description

@sevicbb

Hello,

We are using the voku/anti-xss library for XSS validation and noticed that a specific term is being detected as XSS by its implementation: data:. While the library has generally worked well, this issue resembles a previous problem we encountered with the terms profile( and system(, which were resolved in a newer version.

Could you please investigate this issue? Additionally, is there a way to whitelist or handle such terms on our side as a workaround until a fix is available?

Thank you for your support.

Best regards,
Djordje Sevic

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions