Files
codeql/csharp/ql/test/query-tests/Security Features/CWE-502/UnsafeDeserialization/XmlSerializerBad.cs
2021-03-20 21:50:46 +02:00

14 lines
252 B
C#

using System.Xml.Serialization;
using System.IO;
using System;
class BadXmlSerializer
{
public static object Deserialize(Type type, Stream s)
{
var ds = new XmlSerializer(type);
// BAD
return ds.Deserialize(s);
}
}