Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/xss-through-torrent.js
2019-11-14 13:54:19 +01:00

9 lines
227 B
JavaScript

const parseTorrent = require('parse-torrent'),
express = require('express');
express().get('/user/:id', function(req, res) {
let torrent = parseTorrent(unknown),
name = torrent.name;
res.send(name); // NOT OK
});