alert("Controlado por el intruso")
Hi alert(‘xss’)
@RequestMapping("/hello") @ResponseBody protected String handleHello(HttpServletRequest request){ String name = request.getParameter("name"); return String.format(“Hi %s
", name); }Hi <script>alert("xss")</script>
Hi alert(‘xss’) import org.springframework.web.util.HtmlUtils; @RequestMapping("/hello") @ResponseBody protected String handleHello(HttpServletRequest request){ String name = request.getParameter("name"); return String.format("Hi %s
", HtmlUtils.htmlEscape(name)); }