**Reflected_XSS_All_Clients** issue exists @ **webgoat-lessons/xxe/src/main/java/org/owasp/webgoat/plugin/Ping.java** in branch **master** Severity: High CWE:79 [Vulnerability details and guidance](https://cwe.mitre.org/data/definitions/79.html) [Internal Guidance](https://custodela.atlassian.net/wiki/spaces/AS/pages/79462432/Remediation+Guidance) Lines: [58](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/xxe/src/main/java/org/owasp/webgoat/plugin/Ping.java#L58) --- [Code (Line #58):](https://github.com/Custodela/WebGoat//blob/master/webgoat-lessons/xxe/src/main/java/org/owasp/webgoat/plugin/Ping.java#L58) ``` public String logRequest(@RequestHeader("User-Agent") String userAgent, @RequestParam(required = false) String text) { ``` ---