**Reflected_XSS_All_Clients** issue exists @ **webgoat-lessons/vulnerable-components/src/main/java/org/owasp/webgoat/plugin/VulnerableComponentsLesson.java** in branch **master** Severity: High CWE:79 [Vulnerability details and guidance](https://cwe.mitre.org/data/definitions/79.html) [Internal Guidance](https://custodela.atlassian.net/wiki/spaces/AS/pages/79462432/Remediation+Guidance) Lines: [53](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/vulnerable-components/src/main/java/org/owasp/webgoat/plugin/VulnerableComponentsLesson.java#L53) --- [Code (Line #53):](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/vulnerable-components/src/main/java/org/owasp/webgoat/plugin/VulnerableComponentsLesson.java#L53) ``` public @ResponseBody AttackResult completed(@RequestParam String payload) throws IOException { ``` ---