Sobelow.XSS.SendResp (Sobelow v0.16.0)

View Source

XSS in send_resp

This submodule looks for XSS vulnerabilities in the body argument of Conn.send_resp.

A known data content type on the response connection suppresses the finding. Both put_resp_content_type and put_resp_header with the literal "content-type" header are recognized. HTML and SVG retain their confidence; dynamic, malformed, and other scriptable document types remain low-confidence findings.

SendResp checks can be ignored with the following command:

$ mix sobelow -i XSS.SendResp

Summary

Functions

details()

id()

parse_def(fun)

rule()

run(fun, meta_file)