Files
codeql/python/ql/test/query-tests/Security/CWE-074-TemplateInjection/JinjaSsti.py
2026-06-19 12:22:40 +01:00

32 lines
891 B
Python

from django.urls import path
from django.http import HttpResponse
from jinja2 import Template
from jinja2 import Environment, DictLoader, escape
def a(request): # $ Source
# Load the template
template = request.GET['template']
t = Template(template) # $ Alert # BAD: Template constructed from user input
name = request.GET['name']
# Render the template with the context data
html = t.render(name=escape(name))
return HttpResponse(html)
def b(request): # $ Source
import jinja2
# Load the template
template = request.GET['template']
env = Environment()
t = env.from_string(template) # $ Alert # BAD: Template constructed from user input
name = request.GET['name']
# Render the template with the context data
html = t.render(name=escape(name))
return HttpResponse(html)
urlpatterns = [
path('a', a),
path('b', b)
]