Hello Vasya,
I see that I’m not using igUpload component. I could technically exclude infragistics.ui.upload.js 26 it appears in
JS files within VeraCode_Publish.zip, which is the website_publish package generated by Visual Studio.
Same applies to js/infragistics.lob.js file.
Below are the notes from VeraCode:
Description
This call contains a cross-site scripting (XSS) flaw. The application populates the HTTP response with untrusted input,
allowing an attacker to embed malicious content, such as Javascript code, which will be executed in the context of the
victim’s browser. XSS vulnerabilities are commonly exploited to steal or manipulate cookies, modify presentation of
content, and compromise confidential information, with new attack vectors being discovered on a regular basis.
Recommendations
Use contextual escaping on all untrusted data before using it to construct any portion of an HTTP response. The
escaping method should be chosen based on the specific use case of the untrusted data, otherwise it may not protect
fully against the attack. For example, if the data is being written to the body of an HTML page, use HTML entity
escaping; if the data is being written to an attribute, use attribute escaping; etc. When a web framework provides builtin
support for automatic XSS escaping, do not disable it. Both the OWASP Java Encoder library for Java and the
Microsoft AntiXSS library provide contextual escaping methods. In addition, as a
best practice, always validate untrusted input to ensure that it conforms to the expected format, using centralized data
validation routines when possible.
Thank You for any suggestions,
Martin