Kindly advise how to fix the following *vulnerabilities* in *D Space* Version 6.0
1. *Stored XSS* - Cross-site scripting (also known as XSS) is a web security vulnerability which occurs when a malicious script is injected directly into a vulnerable web application cause of input validation. 2. *Reflected XSS* -- Reflected XSS is one of the part of Cross-Site-Scripting attacks and termed as “Non-Persistence XSS” or “Type II”. 3 R*ate Limiting*- number of wrong login attempts to be limited to 3 4. *CSRF*- cross site request forgery- The most effective way to protect against CSRF vulnerabilities requests an additional token that is not transmitted in a cook in a hidden form field 5. *Click jacking - * * Thanks* * Rajiv Gujral* * Group member* -- All messages to this mailing list should adhere to the Code of Conduct: https://www.lyrasis.org/about/Pages/Code-of-Conduct.aspx --- You received this message because you are subscribed to the Google Groups "DSpace Technical Support" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/dspace-tech/CAMaJchHZdKtpf455SAxTi0zeaT--QhsOsLeMYmhP0pezk8Y1mg%40mail.gmail.com.
