Hi,
when navigating to the API metadata page with some scripting it’s not prventing xss scripting
Example ending
/jsonl/metadata/?op=LicenseQuery&lang=%27%3E%22%3Csvg/onload=confirm(%27XSS%27)%3E](https://myapi.com/jsonl/metadata/?op=LicenseQuery&lang='>"<svg/onload=confirm('XSS')>)(https://myapi.com/jsonl/metadata/?op=LicenseQuery&lang='>"<svg/onload=confirm('XSS')>) ).
How can i prevent this from happening?