T09 · Insecure Skill Coding Practices
- Location
scripts/generate_html.py:234- Finding
Stored Cross-Site Scripting Through Untrusted Remote Data in Generated HTML
- Content
View full analysis
const items = {json.dumps(items, ensure_ascii=False)}; function formatHeat(num) {{ if (num >= 10000) return (num / 10000).toFixed(1) + '万'; return num.toLocaleString(); }} function getRankClass(rank) {{ if (rank === 1) return 'top1'; if (rank === 2) return 'top2'; if (rank === 3) return 'top3'; return 'normal'; }} function renderItems() {{ const dateSelect = document.getElementById('dateSelect').value; const search = document.getElementById('searchInput').value.toLowerCase().trim(); let filtered = items.filter(item => {{ if (dateSelect && item.date !== dateSelect) return false; if (search && !item.title.toLowerCase().includes(search)) return false; return true; }}); document.getElementById('showCount').textContent = filtered.length; const container = document.getElementById('hotList'); if (filtered.length === 0) {{ container.innerHTML = ``; return; }} // 按日期分组 const grouped = {{}}; filtered.forEach(item => {{ if (!grouped[item.date]) grouped[item.date] = []; grouped[item.date].push(item); }}); let html = ''; Object.keys(grouped).sort().reverse().forEach(date => {{ html += grouped[date].map(item => `🎵没有找到记录- Remediation
View remediation
`, and `&`. For example: ```python serialized_items = json.dumps(items, ensure_ascii=False) serialized_items = ( serialized_items .replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") ) ``` A safer design is to store JSON in a separate file and load it as data, subject to the same-origin policy and an appropriate Content Security Policy. 4. Validate and normalize remote fields before database insertion. Enforce expected types, maximum lengths, numeric ranges, and an allowlist of permitted URL schemes and hosts. 5. Add a restrictive Content Security Policy. Remove inline scripts where possible and use a separate JavaScript file so that a policy such as the following can be applied: ```html
