Files
codeql/javascript/ql/test/query-tests/Security/CWE-022/TaintedPath/express.js
2021-12-10 15:05:34 +01:00

10 lines
209 B
JavaScript

var express = require("express"),
fileUpload = require("express-fileupload");
let app = express();
app.use(fileUpload());
app.get("/some/path", function (req, res) {
req.files.foo.mv(req.query.bar);
});