Update javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql

Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com>
This commit is contained in:
monkey-junkie
2020-05-06 12:54:50 +03:00
committed by GitHub
parent 3314dd0614
commit 122354a81a

View File

@@ -28,7 +28,7 @@ class SSTIPugSink extends ServerSideTemplateInjectionSink {
exists(CallNode compile, ModuleImportNode renderImport |
renderImport = moduleImport(["pug", "jade"]) and
(
compile = renderImport.getAMemberCall("compile") and
compile = renderImport.getAMemberCall("compile")
or
compile = renderImport.getAMemberCall("render")
) and