Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This pull request from patched fixes 4 issues.
Path traversal vulnerability fixed in FileUploader servlet
This patch fixes a path traversal vulnerability in the FileUploader servlet by sanitizing the file path using a utility method from org.apache.commons.io.FilenameUtils.Fixed XSS vulnerability by escaping HTML in the servlet's output.
The servlet's output has been modified to use an HTML escape mechanism to prevent user-input from going directly into an OutputStream or Writer object, preventing potential XSS vulnerabilities.Fixed SQL injection vulnerability in getOrderStatus servlet
Fixed the vulnerability by using a Prepared Statement with a parameterized query to prevent SQL injection.Fixed potential code injection vulnerability in ServletTarPit class.
Improved security by removing hardcoded AWS ACCESS KEY ID and SECRET KEY.