I am working with Checkmarx to scan my code for any potential vulnerabilities. I am getting
This untrusted data is embedded straight into the output without proper sanitization or encoding, enabling an attacker to inject malicious code into the output. message with following code.
var currentUrl = location.href;
I have tried to resolve this with following code, but seems like Checkmarx is not able to detect that I am already sanitizing the data.
var currentUrl = checkUrlForXSS(location.href);
// function definition
function checkUrlForXSS(url) {
const reg = /(script|\)|\(|\>|\<)/ig;
return url.replace(reg, "");
}
Is there any way I can sanitize the data in Javascript and resolve the vulnerability without using any libraries (like DOMPurify)?
Thank you.