Review a small page that renders a user profile name, link, and optional rich-text description. For each value, identify who controls it, where it is stored, and the browser context where it is inserted.
Replace unsafe string concatenation with framework-safe rendering. Validate URL schemes and destinations; use a maintained sanitizer only when rich HTML is a real product requirement. Add tests for quotes, angle brackets, event-handler attributes, and javascript: URLs without assuming one escape function is safe in every context.
The linked OWASP guide provides context-specific defenses. A web application firewall is not a substitute for safe output handling in the application.