Description
Writing request parameters directly into an HTML response can cause attacker-controlled scripts to run in the browser.
Potential impact
Attackers may hijack sessions, display phishing content, make requests as the user, or expose user data.
Remediation
Use htmlspecialchars or htmlentities for HTML text and quoted ordinary attribute values. JavaScript, CSS, and URL values require protection appropriate to their output context.
Examples
Before
php
<?php
$html .= '<pre>Hello ' . $_GET['name'] . '</pre>';
After
php
<?php
$name = htmlspecialchars($_GET['name'], ENT_QUOTES, 'UTF-8');
$html .= '<pre>Hello ' . $name . '</pre>';
Explanation:
- Before: Request input is written into the HTML response without output encoding.
- After: The value is HTML-encoded before insertion into the text content of the
preelement.