The product generates a web page, but does not neutralize or incorrectly neutralizes user-controllable input that could be interpreted as a server-side include (SSI) directive.
Our security experts can help you identify and remediate CWE-97 vulnerabilities in your codebase.
Get Security Assessment