'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:Detect XSS Injection with JavaScript Function 'createTextRange'
Severity:mid
CVE ID:
Descripiton:
|
Cross-site scripting(XSS) is a type of computer security vulnerability tipically found in Web application. XSS enables attackers to inject client-side scripts into Web pages viewed by other users. Attackers can use javascript function 'createtextrange' to get web content, then try to distort the content to deceive users. This rule detects javascript function 'createtextrange' in HTTP request. This rule supports to defend the A3: Injection of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.