Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/react-native.js
2020-10-16 17:32:36 +01:00

11 lines
276 B
JavaScript

import express from 'express';
import { WebView } from 'react-native';
var app = express();
app.get('/some/path', function(req, res) {
let tainted = req.param("code");
<WebView html={tainted}/>; // NOT OK
<WebView source={{html: tainted}}/>; // NOT OK
});