Files
codeql/csharp/ql/lib/change-notes/2024-12-12-add-markupstring-as-html-injection-sink.md
2024-12-13 12:48:01 -05:00

242 B

category
category
minorAnalysis
  • Added the constructor and explicit cast operator of Microsoft.AspNetCore.Components.MarkupString as an html-injection sink. This will help catch cross-site scripting resulting from using MarkupString.