- Home
- All questions
- Question 152
CompTIA Security+ study material · question 152 of 611
An application built on a modern framework has a stored cross-site scripting flaw. What is the most likely cause?
Show the answer
Answer: B. The framework's default encoding was deliberately bypassed to render raw HTML
Frameworks encode by default, so most such flaws come from an explicit opt-out for rich content.
Source: OWASP Cross Site Scripting Prevention Cheat Sheet (OWASP) — OWASP Cross Site Scripting Prevention Cheat Sheet › Framework Security