userjack6880 / Open-DMARC-Analyzer

Open DMARC Analyzer is an Open Source DMARC Report Analyzer to be used with DMARC reports that have been parsed by John Levine's rrdmarc script or techsneeze's dmarcts-report-parser.
GNU General Public License v3.0
224 stars 24 forks source link

Input should be sanitized to prevent Cross-Site Scripting #14

Closed mwander closed 3 years ago

mwander commented 3 years ago

User input from $_GET is not sanitized and thus vulnerable to cross-site scripting.

Example: https://example.net/Open-DMARC-Analyzer/host.php?ip=%3Cscript%3Ealert(%22XSS%22)%3C/script%3E