mirror of
https://github.com/github/codeql.git
synced 2025-12-17 09:13:20 +01:00
8 lines
276 B
JavaScript
8 lines
276 B
JavaScript
const express = require('express');
|
|
const libxmljs = require('libxmljs');
|
|
|
|
express().get('/some/path', function (req) {
|
|
const parser = new libxmljs.SaxParser();
|
|
parser.parseString(req.param("some-xml")); // $ Alert: the SAX parser expands external entities by default
|
|
});
|