fix: potential NPE in the stored XSS assignment
This commit is contained in:
parent
49862f6b90
commit
be30551850
@ -39,7 +39,7 @@ public class StoredCrossSiteScriptingVerifier extends AssignmentEndpoint {
|
|||||||
public AttackResult completed(@RequestParam String successMessage) {
|
public AttackResult completed(@RequestParam String successMessage) {
|
||||||
UserSessionData userSessionData = getUserSessionData();
|
UserSessionData userSessionData = getUserSessionData();
|
||||||
|
|
||||||
if (successMessage.equals(userSessionData.getValue("randValue").toString())) {
|
if (successMessage.equals(userSessionData.getValue("randValue"))) {
|
||||||
return success(this).feedback("xss-stored-callback-success").build();
|
return success(this).feedback("xss-stored-callback-success").build();
|
||||||
} else {
|
} else {
|
||||||
return failed(this).feedback("xss-stored-callback-failure").build();
|
return failed(this).feedback("xss-stored-callback-failure").build();
|
||||||
|
Loading…
x
Reference in New Issue
Block a user