Files
codeql/javascript/ql/test/query-tests/Security/CWE-643/tst2.js
2025-02-28 13:29:30 +01:00

4 lines
151 B
JavaScript

let query = document.location.hash.substring(1); // $ Source
document.createExpression(query); // $ Alert
document.evaluate(query); // $ Alert