T09 · Insecure Skill Coding Practices
- Location
references/templates/patents_template.html:99- Finding
Stored Cross-Site Scripting Through Unsafe Report Template Rendering
- Content
View full analysis
``).join(''); renderPagination(); } function renderPagination(){ const total=Math.ceil(filtered.length/perPage); const pg=document.getElementById('pagination'); pg.innerHTML=Array.from({length:total},(_,i)=>`${i+1}`).join(''); } ``` From `references/templates/evidence_template.html:94-110`: ```javascript const evidenceData = {{EVIDENCE_JSON}}; function renderEvidence(filter){ const list=document.getElementById('evidenceList'); const data=filter==='all'?evidenceData:evidenceData ...[truncated 4599 chars]${p.pn||'—'} ${p.status==='active'?'有效':p.status==='inactive'?'失效':'审中'}${p.title||'—'}📅 ${p.date||'—'} 🏢 ${p.assignee||'—'} 🌍 ${p.jurisdiction||'—'} 🔖 ${p.ipc||'—'}${p.abstract||'—'}- Remediation
View remediation
SAFE_JSON ``` The serializer must escape at least `<`, `>`, `&`, U+2028, U+2029, and case-insensitive ` "> javascript:alert(1) ``` The tests should verify that payloads appear only as text and cannot create executable DOM nodes. ]]>
