Alice discovers a reflected XSS flaw in her web application. Which of the follow
ID: 3745582 • Letter: A
Question
Alice discovers a reflected XSS flaw in her web application. Which of the following is a valid method for Alice to patch the reflected XSS vulnerability? (Use only a, b, c, or d as answer) a. Ensure that the entire website uses HTTPS. b. Classify data processed, stored, or transmitted by an application. Identify which data is sensitive according to privacy laws, regulatory requirements, or business needs. c. Escape untrusted HTTP request data with respect to context in the HTML output. d. Implement multi-factor authentication.
Explanation / Answer
Correct option is (c)
Explanation:
XSS vulnerability injects malicious code to legitimate webapp.
It can be prevented by making sure malicious input isn't interpreted in any executable manner. So, we can escape untrusted request data so that malicious data isn't executed as code.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.