Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/xmlRequest.js
Erik Krogh Kristensen d7b0f628a1 add test
2021-03-12 00:03:20 +01:00

16 lines
461 B
JavaScript

$(document).ready(function () {
var xhr = new XMLHttpRequest();
var url = "{{ some_url }}"
xhr.open("GET", url, true)
xhr.setRequestHeader("Content-Type", "application/json")
xhr.onreadystatechange = function () {
if (xhr.readyState !== 4) { return }
var json = JSON.parse(xhr.responseText)
$("#myThing").html(json.message);
}
try {
xhr.send()
} catch (error) {
console.log(error)
}
})