Description
An attacker can control one or more parameter values of a sensitive HTML tag (e.g. link href). In some conditions this can cause security issues such as XSS (cross-site scripting).
Remediation
Your script should properly sanitize user input. Do not allow user-input to fully control important parameter tag values.
References
OWASP - Cross Site Scripting (XSS)
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Related Vulnerabilities
Drupal Core 4.5.x Cross-Site Scripting (4.5.0 - 4.5.1)
Joomla! Core 3.x.x Cross-Site Scripting (3.0.0 - 3.9.11)
WordPress Plugin Favicon by RealFaviconGenerator Cross-Site Scripting (1.2.12)
WordPress Plugin Keyword Strategy Internal Links Multiple Cross-Site Scripting Vulnerabilities (2.0)
WordPress Plugin Mimetic Books Cross-Site Scripting (0.2.13)