Files
codeql/csharp/ql/lib/change-notes/2024-12-12-add-markupstring-as-html-injection-sink.md
2024-12-12 16:22:09 -05:00

215 B

category
category
minorAnalysis
  • Added the constructor of Microsoft.AspNetCore.Components.MarkupString as an html-injection sink. This will help catch cross-site scripting resulting from using MarkupString.