diff --git a/src/main/java/com/ai/net/xss/wrapper/XssRequestWrapper.java b/src/main/java/com/ai/net/xss/wrapper/XssRequestWrapper.java index 6678db0..bbe313a 100644 --- a/src/main/java/com/ai/net/xss/wrapper/XssRequestWrapper.java +++ b/src/main/java/com/ai/net/xss/wrapper/XssRequestWrapper.java @@ -109,6 +109,7 @@ public class XssRequestWrapper extends HttpServletRequestWrapper { String str = StringEscapeUtils.escapeHtml(cr.getCleanHTML()); str = str.replaceAll((antiSamy.scan(" ", policy)).getCleanHTML(), ""); str = StringEscapeUtils.unescapeHtml(str); + str = str.replaceAll(""", "\""); log.info("xssfilter value after xssClean:" + str); return str; }