**Reflected_XSS_All_Clients** issue exists @ **webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/challenge7/Assignment7.java** in branch **master** Severity: High CWE:79 [Vulnerability details and guidance](https://cwe.mitre.org/data/definitions/79.html) [Internal Guidance](https://custodela.atlassian.net/wiki/spaces/AS/pages/79462432/Remediation+Guidance) Lines: [63](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/challenge7/Assignment7.java#L63) --- [Code (Line #63):](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/challenge/src/main/java/org/owasp/webgoat/plugin/challenge7/Assignment7.java#L63) ``` public AttackResult sendPasswordResetLink(@RequestParam String email, HttpServletRequest request) throws URISyntaxException { ``` ---