• Hi @emaciel (Community Member)​ 

     

    As we see that you writing a log entry, which is not applicable to XSS unless the logs are to be read by Admin or some other roles to view these logging statements in the view page(browser).

     

    If it is not viewed in that fashion, this can be mitigated by sufficient explanation.

     

    Alternatively, you can use a supported cleansing function from https://help.veracode.com/r/review_cleansers and choose the functions that address CWE 80.

     

    It is best to get more details on how the taint is originating from the 'Description' of the specific flaw from the Triage Flaws page.

    If after reviewing the details in the Triage Flaws view in the Veracode Platform you still have questions I would recommend you schedule a consultation call to discuss.

     

    You can check out this knowledge article (https://community.veracode.com/s/article/How-to-schedule-a-consultation-call) on how to schedule a consultation call with us.

     

    Regards,

    Kashif

     

    Expand Post

Topics (2)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.