{"id":{"repo_id":"sfasu","oai_identifier":"oai:scholarworks.sfasu.edu:etds-1644"},"canonical_url":"https://search.dev.ndltd.org/etd/sfasu/oai:scholarworks.sfasu.edu:etds-1644","repository":{"repo_id":"sfasu","name":"Stephen F. Austin State University","base_url":"https://scholarworks.sfasu.edu/do/oai/"},"display":{"title":"Managing Software Dependency Risks in Web Applications","abstract":"<p>Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security improvements, and it presents strategies for mitigating dependency related vulnerabilities. These solutions focus on package management tools available to developers, and they advocate implementing emerging security standards as part of the development life cycle.</p>","abstract_html":"&lt;p&gt;Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security improvements, and it presents strategies for mitigating dependency related vulnerabilities. These solutions focus on package management tools available to developers, and they advocate implementing emerging security standards as part of the development life cycle.&lt;/p&gt;","abstract_has_math":false,"creators":["Scott, Christopher Alan"],"institution":null,"degree_name":"Master of Science – Cyber Security","degree_level":"Thesis","degree_discipline":"College of Science and Mathematics","degree_department":null,"school":null,"contributors":["Christopher Ivancic","Pushkar Ogale","Nikki Shoemaker"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2025,"date_issued":"2025-05-01T07:00:00Z","date_published":"2025-05-01T07:00:00Z","updated_at":"2026-07-24T04:30:49Z","subjects":["dependency chain","information security","risk management","supply chain","vulnerability management","web application development","Cybersecurity"],"languages":[],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://scholarworks.sfasu.edu/etds/610","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Christopher Ivancic","Pushkar Ogale","Nikki Shoemaker"]},{"key":"dc:creator","label":"Author","values":["Scott, Christopher Alan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.available","label":"Dc Date Available","values":["2025-04-25T07:00:00Z"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["College of Science and Mathematics"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science – Cyber Security"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["dependency chain","information security","risk management","supply chain","vulnerability management","web application development","Cybersecurity"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://scholarworks.sfasu.edu/etds/610"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security improvements, and it presents strategies for mitigating dependency related vulnerabilities. These solutions focus on package management tools available to developers, and they advocate implementing emerging security standards as part of the development life cycle.</p>"]},{"key":"dc:title","label":"Title","values":["Managing Software Dependency Risks in Web Applications"]}]}],"canonical_facts":{"dc:contributor":["Christopher Ivancic","Pushkar Ogale","Nikki Shoemaker"],"dc:creator":["Scott, Christopher Alan"],"dc:date.available":["2025-04-25T07:00:00Z"],"dc:description.abstract":["<p>Web applications commonly rely on third-party software dependencies to reduce development time. This thesis examines how vulnerabilities in a dependency chain propagate to compromise an application. It analyzes two vulnerable Markdown libraries from the npm and Composer dependency ecosystems, both of which are used for managing packages in applications developed with JavaScript and PHP. The analysis demonstrates how each library’s sanitizing functions—intended for removing unsafe user input when transforming Markdown text to HTML—are defeated to achieve a cross-site scripting exploit and take control of the application. The paper discusses potential business impacts of a compromise, underscoring the need for security improvements, and it presents strategies for mitigating dependency related vulnerabilities. These solutions focus on package management tools available to developers, and they advocate implementing emerging security standards as part of the development life cycle.</p>"],"dc:identifier":["https://scholarworks.sfasu.edu/etds/610"],"dc:subject":["dependency chain","information security","risk management","supply chain","vulnerability management","web application development","Cybersecurity"],"dc:title":["Managing Software Dependency Risks in Web Applications"],"thesis:degree_discipline":["College of Science and Mathematics"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["Master of Science – Cyber Security"]},"updated_at":"2026-07-24T04:30:49Z"}