T09 · Insecure Skill Coding Practices
- Location
scripts/reporter.py:214- Finding
Stored Cross-Site Scripting Through Unescaped Review Content
- Content
View full analysis
{"".join(f'''''' for r in negative_reviews[:15]) if negative_reviews else '{r["content"]}评分:{r.get("rating","-")} 情感:{r.get("score","-")} {r.get("time","-")}'} ``` The affected content originates from imported review data and is added to the report data in `scripts/analyzer.py`: ```python result["negative_reviews"].append({ "content": str(row['content'])[:200], "score": round(row.get('sentiment_score', 0), 2), "time": str(row.get('review_time', '')), "rating": row.get('rating', None), }) ``` ### Technical Analysis Review content is attacker-controlled data imported from CSV, Excel, or JSON files. The reporter inserts `r["content"]` directly into an HTML element through an f-string without HTML escaping or sanitization. Truncating the review to 200 characters does not prevent HTML or JavaScript injection. A short payload containing a script-capable element or an event-handler attribute can remain valid within that limit. Because imported reviews are also merged into `history.csv`, the injected content can persist and be included in later reports generated through history or check operations. The vulnerability is therefore a stored injection issue rather than only a one-time reflected issue. The report also lacks a restrictive Content Security Policy that could mitigate inline script and event-handler execution. ### Attack Path 1. An attacker submits a malicious review to a supported platform, or supplies a crafted CSV, Excel, or JSON review file. 2. The review includes ...[truncated 1348 chars]暂无差评 🎉- Remediation
View remediation
``` 5. Avoid inline JavaScript and inline event handlers so that a strict CSP can be enforced. 6. Add security tests using reviews containing closing tags, event-handler attributes, script tags, encoded markup, and malformed HTML. 7. Sanitize previously stored review content when regenerating reports; do not assume existing `history.csv` data is trusted. ]]>
