Printf Output to ResponseWriter
fmt.Printf or fmt.Sprintf output containing user data is written to ResponseWriter without escaping.
XSS vulnerability in Go net/http applications where fmt.Printf output is written to http.ResponseWriter without HTML escaping, rendering user-controlled data directly into pages and allowing malicious scripts to execute in user browsers.
Configuration changes required - see explanation below.
Configuration changes required - see explanation below.
fmt.Printf or fmt.Sprintf output containing user data is written to ResponseWriter without escaping.
Sourcery automatically identifies cross-site scripting (xss) via printf in http.responsewriter.write output and many other security issues in your codebase.