OWASP / www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

Home Page:https://owasp.org/www-community/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

How to solve the problem of double encoding

2MoonStop opened this issue · comments

commented

When I pass in the value of "%27%Balert%28361%29%2B%27", it cannot handle this value.
look forward to your reply

commented

what should i do? first of all decode this value?

That's probably covered in: https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html

If you want to discuss further I'd suggest posting to #appsec on the OWASP slack. (Self invite here)