Skip to content

AutoFix PR#36

Open
nishfath wants to merge 2 commits into
mainfrom
qwietai/autofix/fix0005
Open

AutoFix PR#36
nishfath wants to merge 2 commits into
mainfrom
qwietai/autofix/fix0005

Conversation

@nishfath
Copy link
Copy Markdown
Owner

@nishfath nishfath commented May 20, 2026

Harness SAST and SCA AutoFix

This PR was created automatically by the Harness SAST and SCA AutoFix tool.
As long as it is open, subsequent scans and generated fixes to this same branch will be added to it as new commits.

Each commit fixes one vulnerability.

Some manual intervention might be required before merging this PR.

Project Information

Findings/Vulnerabilities Fixed

Finding 6: Cross-Site Scripting: Attacker-Controlled Data Used as HTML Content via customerId in CustomerController.debug

Vulnerability Description

Attacker-Controlled data is used as HTML content. This indicates a Cross-Site-Scripting (XSS) vulnerability.

  • Severity: high
  • CVSS Score: 8 (high)
  • CWE: 79
  • Category: Cross-Site Scripting
Commits/Files Changed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant