Files
codeql/javascript/ql/test/query-tests/Security/CWE-776/expat.js
2020-07-08 10:10:31 +02:00

8 lines
250 B
JavaScript

const express = require('express');
const expat = require('node-expat');
express().get('/some/path', function(req) {
var parser = new expat.Parser();
parser.write(req.param("some-xml")); // NOT OK: expat expands internal entities by default
});