XSS best practices?
Hi, we are looking into better XSS (Cross-site scripting) prevention.
- We have the "Enable Global Script" protection checked in CFAdmin
- We have modified neo-security.xml to include a regex to remove various unwanted tags
- We have queryparamed all querys
- We are using getSafeHTML() when needed
- We are about to go in block mode behind a WAF
Does anyone have other recommendations? I couldn't find any recent posts about this in these forums.
