Skip to content
Closed
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
Python: Reorder XSLT qhelp to be valid
  • Loading branch information
RasmusWL authored Jun 11, 2020
commit 33a9fb6034b3a58bc273abe926d5f30d9667d12b
10 changes: 5 additions & 5 deletions python/ql/src/experimental/CWE-643/Xslt.qhelp
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,9 @@
This vulnerability can be prevented by not allowing untrusted user input to be passed as a XSL stylesheet.
If the application logic necessiates processing untrusted XSL stylesheets, the input should be properly filtered and sanitized before use.
</p>
<example>
<p>In the example below, the XSL stylesheet is controlled by the user and hence leads to a vulnerability.</p>
<sample src="xslt.py" />
</example>
</recommendation>
</qhelp>
<example>
<p>In the example below, the XSL stylesheet is controlled by the user and hence leads to a vulnerability.</p>
<sample src="xslt.py" />
</example>
</qhelp>