SPC028903: Disallow use of script URLs |
This causes the browser to eval the code target, opening up a point for a cross site scripting attack
CheckId | SPC028903 |
---|---|
TypeName | NoScriptUrls |
Severity | Error |
Type | JavaScriptFile |
Bad Practice
eval('function foo() { alert("Hello World!"); }');
foo();
foo();
Disclaimer: The views and opinions expressed in this documentation and in SPCAF do not necessarily reflect the opinions and recommendations of Microsoft or any member of Microsoft. SPCAF and RENCORE are registered trademarks of RENCORE AB. All other trademarks, service marks, collective marks, copyrights, registered names, and marks used or cited by this documentation are the property of their respective owners.