FP in C# XSS Sink
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
**Description of the false positive**
Use of asp-route-{parameter} in cshtml documents are url encoded, preventing breakout from string and thus preventing XSS despite the use of WriteLiteral in the compiled code.
**Code samples or links to source code**
```csharp
```
[MRVA Result](https://gist.githubusercontent.com/Kwstubbs/6e2307d324ceb6c3b4a8c50f9cb798ff/raw/1275c04dea523d6176ad8707820790e35d3aa4b4/result-2-AiursoftWeb-Infrastructures.md)
Hướng dẫn đóng góp
Hướng nghiên cứu
Start by reviewing the issue's C# and cshtml samples alongside the linked MRVA result. Locate the CodeQL query and tests that classify asp-route-{parameter} as an XSS sink; done means this encoded route usage is no longer reported while genuine XSS cases remain covered.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- csharp
- Lĩnh vực
- security
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 35/100