3.2 XSS Detection
Is my application vulnerable to XSS ?
XSS vulnerabilities are difficult to identify and completely be removed from web applications or API.
- Review new code by a knowledgeable person in secure coding.
- SAST scans are capable to detect vulnerable code which could allow XSS attacks.
- DAST tools such as OWASP ZAP can scan your application and help you detect exploitable flaws allowing XSS.