Files
codeql/csharp/ql/test/query-tests/Security Features/CWE-502/UnsafeDeserialization/UnsafeDeserializationBad.cs
2019-10-22 09:55:39 +01:00

12 lines
254 B
C#

using System.Web.Script.Serialization;
class Bad
{
public static object Deserialize(string s)
{
JavaScriptSerializer sr = new JavaScriptSerializer(new SimpleTypeResolver());
// BAD
return sr.DeserializeObject(s);
}
}