Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/express.js
Erik Krogh Kristensen e124ba66b4 moving jsdom sink to js/xss
2020-11-05 16:10:33 +01:00

12 lines
295 B
JavaScript

var express = require('express');
var app = express();
import { JSDOM } from "jsdom";
app.get('/some/path', function (req, res) {
// NOT OK
new JSDOM(req.param("wobble"), { runScripts: "dangerously" });
// OK
new JSDOM(req.param("wobble"), { runScripts: "outside-only" });
});