mirror of
https://github.com/github/codeql.git
synced 2026-05-02 04:05:14 +02:00
Fix typo.
This commit is contained in:
@@ -26,9 +26,9 @@ import semmle.python.web.HttpResponse
|
||||
import semmle.python.security.strings.Untrusted
|
||||
|
||||
|
||||
class RefectedXssConfiguration extends TaintTracking::Configuration {
|
||||
class ReflectedXssConfiguration extends TaintTracking::Configuration {
|
||||
|
||||
RefectedXssConfiguration() { this = "Reflected XSS configuration" }
|
||||
ReflectedXssConfiguration() { this = "Reflected XSS configuration" }
|
||||
|
||||
override predicate isSource(TaintTracking::Source source) { source instanceof HttpRequestTaintSource }
|
||||
|
||||
@@ -36,6 +36,6 @@ class RefectedXssConfiguration extends TaintTracking::Configuration {
|
||||
|
||||
}
|
||||
|
||||
from RefectedXssConfiguration config, TaintedPathSource src, TaintedPathSink sink
|
||||
from ReflectedXssConfiguration config, TaintedPathSource src, TaintedPathSink sink
|
||||
where config.hasFlowPath(src, sink)
|
||||
select sink.getSink(), src, sink, "Cross-site scripting vulnerability due to $@.", src.getSource(), "user-provided value"
|
||||
|
||||
Reference in New Issue
Block a user