Skip to content

Infragistics Community Forum / Web / Ignite UI for jQuery / Improper Neutralization of Script-Related HTML Tags in a Web Page

Improper Neutralization of Script-Related HTML Tags in a Web Page

New Discussion
Martin Zietarski
Martin Zietarski asked on Oct 8, 2019 1:49 PM

Hey Guys,

We do often scan our web pages by using VeraCode, lately we resolved few of the cross-site scripting (XSS) flaws identified.

In regards of 2x files coming out of Scripts/Infragistics package folder and being addressed we are searching for suggestions or advise..

/…/js/infragistics.lob.js 834
…/modules/infragistics.ui.upload.js 26

It would be helpful to know how to address these issues.

Thank You

Martin

Sign In to post a reply

Replies

  • 0
    Vasya Kacheshmarova
    Vasya Kacheshmarova answered on Oct 2, 2019 1:52 PM

    Hello Martin,

    Thank you for posting in our community.

    Since VeraCode is a paid tool I am not able to scan the mentioned files. Can you please provide me with the log of the identified flaws, This is going to be very helpful in order to decide how we should proceed further. 

    Additionally, can you please let me know whether you are using the igUpload component in your application?

    Looking forward to hearing from you.

    • 0
      Martin Zietarski
      Martin Zietarski answered on Oct 7, 2019 2:20 PM

      Hello Vasya,

      I see that I’m not using igUpload component. I could technically exclude infragistics.ui.upload.js 26 it appears in

      JS files within VeraCode_Publish.zip, which is the website_publish package generated by Visual Studio.

      Same applies to js/infragistics.lob.js file.

      Below are the notes from VeraCode:

      Description
      This call contains a cross-site scripting (XSS) flaw. The application populates the HTTP response with untrusted input,
      allowing an attacker to embed malicious content, such as Javascript code, which will be executed in the context of the
      victim’s browser. XSS vulnerabilities are commonly exploited to steal or manipulate cookies, modify presentation of
      content, and compromise confidential information, with new attack vectors being discovered on a regular basis.

      Recommendations
      Use contextual escaping on all untrusted data before using it to construct any portion of an HTTP response. The
      escaping method should be chosen based on the specific use case of the untrusted data, otherwise it may not protect
      fully against the attack. For example, if the data is being written to the body of an HTML page, use HTML entity
      escaping; if the data is being written to an attribute, use attribute escaping; etc. When a web framework provides builtin
      support for automatic XSS escaping, do not disable it. Both the OWASP Java Encoder library for Java and the
      Microsoft AntiXSS library provide contextual escaping methods. In addition, as a
      best practice, always validate untrusted input to ensure that it conforms to the expected format, using centralized data
      validation routines when possible.

      Thank You for any suggestions,

      Martin

      • 0
        Vasya Kacheshmarova
        Vasya Kacheshmarova answered on Oct 8, 2019 1:49 PM

        Hello Martin,

        Infragistics.lob.js is a file containing the minified scripts for all line of business controls, including igUpload. In case that you are not using the upload my suggestion is using our scrip combining tool to create a custom scripts bundle for your scenario without the igUpload. Script combiner is a tool that allows you to create a custom build with only these components and features required for your project, which will maximize the performance and minimize the download size. The custom build tool can be found here. 

        In order to create the bundle you will have to select all the components and features that you are using and download the custom build. 

        Please test this approach on your side and let me know whether it helps you resolve your issue with the Vera Code report.

  • You must be logged in to reply to this topic.
Discussion created by
Favorites
Replies
Created On
Last Post
Discussion created by
Martin Zietarski
Favorites
0
Replies
3
Created On
Oct 08, 2019
Last Post
6 years, 11 months ago

Suggested Discussions

Created by

Created on

Oct 8, 2019 1:49 PM

Last activity on

Feb 11, 2026 8:48 AM