CodingTrain / CodingTrain/Suggestion-Box

Some projects vulnerable to Cross Site Scripting (XSS)

Open
#293 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
570
Forks
85
PR merge metrics
No merged PRs in 30d

Description

You should really cover [XSS](https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)) as it is a really relevant attack. Especially since some of your older videos using user data are vulnerable to it [(A2Z-F16 week 3](https://github.com/shiffman/A2Z-F16/tree/gh-pages/week3-apis-data) using Google Spreadsheets).

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reading the linked OWASP Cross-Site Scripting reference and reviewing the A2Z-F16 week 3 APIs-data project mentioned in the issue. Define what XSS coverage should include for the older videos using user data; the issue does not identify files, tests, or a concrete completion criterion.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.