
steezedout (Community Member) asked a question.
This question arose from reviewing several CWE 80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerabilities from both static and dynamic scans. We believe the severity level of the dynamic flaw result should be higher than the static level and we can only assign custom severities for the CWE as a whole. The flaw being exposed at the dynamic level is much more exploitable than the static flaws we have review and several Veracode ASCs have suggested posting this feature request due to these findings and how they should be treated differently at the static and dynamic levels. This helps us prioritize which vulnerabilities to tackle first.
.png)
Hello @steezedout (Community Member) ,
Thank you for the suggestion for a feature request! To ensure that it is properly logged, can you please click on the Ideas tab in the Community and add it there? That way the more upvotes that an idea gets, the more likely it can be chosen as a future feature request. Thank you!
Jason
Veracode Support Engineer