C++: Add isBarrier to CgiXss.ql.

This commit is contained in:
Mathias Vorreiter Pedersen
2021-02-16 18:58:28 +01:00
parent f0ce524c0d
commit fa44cedd38
3 changed files with 36 additions and 20 deletions

View File

@@ -34,6 +34,10 @@ class Configuration extends TaintTrackingConfiguration {
override predicate isSink(Element tainted) {
exists(PrintStdoutCall call | call.getAnArgument() = tainted)
}
override predicate isBarrier(Expr e) {
super.isBarrier(e) or e.getUnspecifiedType() instanceof IntegralType
}
}
from QueryString query, Element printedArg, PathNode sourceNode, PathNode sinkNode