Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/translate.js
2020-10-16 17:32:36 +01:00

13 lines
337 B
JavaScript

(function() {
var translate = {
"own goal": "backpass",
"fumble": "feint"
};
var target = document.location.search
var searchParams = new URLSearchParams(target.substring(1));
// NOT OK
$('original-term').html(searchParams.get('term'));
// OK
$('translated-term').html(translate[searchParams.get('term')]);
})();