WEM Listeners - handle on Project Folder?

Hello, we are facing a security issue - when Project Folder is being created our security testers were able to enter some Cross-Site-Scripting code. This functionality is out-of-the-box but OT is currently reluctant to fix it.

Instead they are suggesting us to use a listener. I have looked at the list of available listeners and have not been able to find a listener, which would provide a handle on Project Folder being created. Does anyone have any idea on how to get?

Thank you,

