4k4xs4pH1r3 / artemisa

Audit: Including request data within HTML response strings may lead to XSS attacks JAVA-A1035
Security
Critical
a month ago2 months old
119		response.reset();
120		response.setContentLength(stream.size());
121		response.setCharacterEncoding("utf-8");
122		response.setHeader("Content-disposition", "attachment; filename="123				+ filename + "." + mime.name().toLowerCase());124		response.setHeader("Content-type", mime.getType());
125		// set encoding before writing to out, check this
126		ServletOutputStream out = response.getOutputStream();