Update javascript/ql/src/experimental/Security/CWE-020/PostMessageNoOriginCheck.ql

Co-authored-by: Esben Sparre Andreasen <esbena@github.com>
This commit is contained in:
Alessio Della Libera
2020-06-16 18:27:21 +02:00
committed by GitHub
parent 8843522d14
commit 68b2a6c848

View File

@@ -65,5 +65,5 @@ class PostMessageEvent extends DataFlow::SourceNode {
}
from PostMessageEvent event
where not event.hasOriginChecked()
where not event.hasOriginChecked() or event.hasOriginInsufficientlyChecked()
select event, "Missing or unsafe origin verification"