KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
It turns out the following which looks like valid javascript, is not: <html> <body> <script> json = {test: "</script><script>alert('hello');</script>"}; </script> </body> </html> The same text, when returned JSON via an ajax api works just as expected. However when rendered in-line results in a basic XSS issues. Given an arbitrary correct JSON string, what do I need to do server side to make it safe for in-line rendering? EDIT Ideally I would like the fix to work with the following string as well: json = {test: "<\/script><script>alert('hello');<\/script>"}; Meaning, I have no idea how my underlying library is encoding the / char, it may have chosen to encode it, or it may have not. (so its likely a regex fix is more robust)
Tags (comma-separated)
Save Edits
Cancel