When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and change our default settings. However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
More information
Hi @GDiaz136520 (Community Member) -
The vulnerability "Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)" is identified by CWE ID 80. This is a common type of cross-site scripting (XSS) vulnerability that occurs when an application does not properly sanitize user input before including it in a web page. This can allow an attacker to inject malicious scripts that can then be executed by other users' browsers.
To fix this vulnerability, you should:
Additional info here:
https://www.veracode.com/security/java/cwe-80/
We also have some suggested mitigations here:
https://community.veracode.com/s/question/0D53n00009hkFbHCAU/how-to-fix-cwe80-in-javascript-while-using-html
Dear SamHouston,
Thank you very much for your help.
Really appreciate it, I will share this information with the development team.
Best regards,
Gerardo D