Rule Name:Detect XSS Injection with 'datasrc=' Attribute
Severity:high
CVE ID:
Descripiton:
Cross-site scripting(XSS) is a type of computer security vulnerability tipically found in Web application. XSS enables attackers to inject client-side scripts into Web pages viewed by other users. HTML tag attribute 'datasrc' is used to define the data source url. Attackers can use 'datasrc' to include malicious data to harm users. This rule detects 'datasrc=' in HTTP request. This rule supports to defend the A3: Injection of OWASP Top 10 - 2021. Other reference:None