Critical Vulnerability Issue Findings - Fortify Security Scan with HTML Purifier

50 views
Skip to first unread message

Paolo Marco Manarang

unread,
Feb 16, 2023, 4:41:19 PM2/16/23
to htmlpurifier

Hi, we are using HTML Purifier to sanitize the html codes we are saving in our application, With this week security scan with Fortify it detected a Cross Site Scripting (Reflected) vulnerability issue on DomLex.php (Lexer folder) that uses the loadHTML () function on line 79 and 81. Upon checking the current new version 4.15 the loadHTML() is also still use.

 Any idea how to fix this issue??  

 I also attached the details coming from the Fortify Scan.

 htmlpurifier-4.15.0/library/HTMLPurifier/Lexer/DOMLex.php


image001.png

Screen Shot 2023-02-16 at 3.57.45 PM.png

Screen Shot 2023-02-16 at 3.57.53 PM.png

Reply all
Reply to author
Forward
0 new messages