'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:Detect XSS Injection with JavaScript Function 'fromCharCode'
Severity:high
CVE ID:
| Descripiton:
|
Cross-site scripting(XSS) is a type of computer security vulnerability tipically found in Web application. XSS enables attackers to inject client-side scripts into Web pages viewed by other users. JavaScript function 'fromCharCode' is used to convert a Unicode value to a Unicode string. Attackers can use 'fromCharCode' function to bypass server's check to inject malicious javascript code. This rule detects 'fromCharCode' function in HTTP request. This rule supports to defend the A3: Injection of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.