渗透测试漏洞修复

This commit is contained in:
马三炮 2025-11-26 17:57:29 +08:00
parent ff19105298
commit 5b4fc26ffa
1 changed files with 3 additions and 1 deletions

View File

@ -82,7 +82,9 @@ public class XssFilter implements GlobalFilter, Ordered
DataBufferUtils.release(join); DataBufferUtils.release(join);
String bodyStr = new String(content, StandardCharsets.UTF_8); String bodyStr = new String(content, StandardCharsets.UTF_8);
try { try {
if (bodyStr.contains("username") || bodyStr.contains("password")){ if (bodyStr.contains("username") || bodyStr.contains("password") || bodyStr.contains("userName")
|| bodyStr.contains("idNumber") || bodyStr.contains("orgId") || bodyStr.contains("phone") ||
bodyStr.contains("phonenumber")){
}else { }else {
bodyStr = java.net.URLDecoder.decode(bodyStr, StandardCharsets.UTF_8.name()); bodyStr = java.net.URLDecoder.decode(bodyStr, StandardCharsets.UTF_8.name());