-
Notifications
You must be signed in to change notification settings - Fork 33
Open
Description
| href={getFullPath(appUrl)} |
Unsanitized input from the document location flows into a React dynamic 'href' attribute, where it is used to dynamically construct the HTML page on client side. This may result in a DOM Based Cross-Site Scripting attack (DOMXSS).
(from Snyk)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels