Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/etherpad.js
2018-08-02 17:53:23 +01:00

13 lines
303 B
JavaScript

let express = require('express');
let isVarName = require('is-var-name');
let app = express();
app.get("/some/path", (req, res) => {
let response = "Hello, world!";
if(req.query.jsonp && isVarName(req.query.jsonp))
response = req.query.jsonp + "(" + response + ")";
res.send(response);
});