Generalize QueryInjectionSink

Extends from the more general DataFlow::Node instead of
DataFlow::ExprNode
This commit is contained in:
Remco Vermeulen
2020-07-09 12:32:17 +02:00
parent c01844a39e
commit 9a84abf259
2 changed files with 5 additions and 5 deletions

View File

@@ -40,7 +40,7 @@ class UncontrolledStringBuilderSourceFlowConfig extends TaintTracking::Configura
from QueryInjectionSink query, Expr uncontrolled
where
(
builtFromUncontrolledConcat(query.getExpr(), uncontrolled)
builtFromUncontrolledConcat(query.asExpr(), uncontrolled)
or
exists(StringBuilderVar sbv, UncontrolledStringBuilderSourceFlowConfig conf |
uncontrolledStringBuilderQuery(sbv, uncontrolled) and