You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修复Fortify「Dynamic Code Evaluation: Script Injection」错误?

Fixing Fortify's "Dynamic Code Evaluation: Script Injection" for jQuery load() with location.href

Alright, let's tackle this Fortify script injection issue you're hitting. The problem here is rooted in how you're using location.href directly in jQuery's load() method—let's break down why this is risky and how to fix it properly.

Why the Original Code Triggers the Fortify Alert

Your current code uses location.href + ' #commentListDiv' to construct the URL for load(). The issue is that location.href is user-controllable: an attacker could craft a malicious URL (via XSS or direct manipulation) that injects script content into the string. jQuery's load() method automatically executes any <script> tags in the loaded content, so unfiltered input here creates a clear script injection risk. Fortify flags this because it detects untrusted input being passed to a function that can execute dynamic code.


Fix Options

Option 1: Use a Relative Path (Simplest Fix)

Since you're reloading a section of the current page, you don't need to explicitly use location.href at all. jQuery's load() will default to the current page when you pass just the selector prefixed with a space:

onCommentSuccess: function (showAllComments) {
    $('#commentListDiv').load(' #commentListDiv', function() {
        ACC.quote.displayComments('' + showAllComments);
    });
}

This works because the space tells jQuery to load the current page, then extract the #commentListDiv element. It completely avoids relying on location.href, eliminating the injection vector.

Option 2: Safely Construct the Current URL (If You Need to Preserve Parameters)

If you need to retain query parameters or hash fragments from the current URL, use browser-parsed window.location properties instead of raw location.href. These properties are sanitized by the browser and won't contain unencoded malicious content:

onCommentSuccess: function (showAllComments) {
    // Build a safe URL using browser-resolved components
    const safeBaseUrl = `${window.location.origin}${window.location.pathname}${window.location.search}${window.location.hash}`;
    // Append the selector (note the space separator)
    $('#commentListDiv').load(`${safeBaseUrl} #commentListDiv`, function() {
        ACC.quote.displayComments('' + showAllComments);
    });
}

By using origin, pathname, search, and hash, you're ensuring the URL is constructed from trusted, parsed values instead of a raw user-controllable string.

Option 3: Manual Content Extraction (Most Secure)

For full control over what gets loaded and executed, skip the load() method's built-in selector parsing and use $.get() to fetch the page, then manually extract the content you need. This prevents any accidental script execution from the loaded content:

onCommentSuccess: function (showAllComments) {
    $.get(window.location.href, function(responseHtml) {
        // Extract only the #commentListDiv content from the response
        const updatedCommentList = $(responseHtml).find('#commentListDiv').html();
        // Update the DOM with the sanitized content
        $('#commentListDiv').html(updatedCommentList);
        // Run your post-load logic
        ACC.quote.displayComments('' + showAllComments);
    });
}

This approach is safer because you're explicitly pulling only the HTML you need, and $.get() doesn't automatically execute scripts in the response (unlike load()).


Verification

After applying any of these fixes, re-run your Fortify scan—you should no longer see the "Dynamic Code Evaluation: Script Injection" alert, as we've eliminated the untrusted input vector feeding into the load() method.

内容的提问来源于stack exchange,提问作者DritiP

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:32:23