Files
codeql/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/react-native.js
2018-11-20 14:24:37 +00:00

12 lines
307 B
JavaScript

import express from 'express';
import { WebView } from 'react-native';
var app = express();
app.get('/some/path', function(req, res) {
let tainted = req.param("code");
<WebView injectedJavaScript={tainted}/>; // NOT OK
let wv = <WebView/>;
wv.injectJavaScript(tainted); // NOT OK
});