Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/pages/[id].jsx
2025-02-28 13:29:30 +01:00

30 lines
623 B
JavaScript

import { useRouter } from 'next/router'
export default function Post(params) {
const router = useRouter()
const { id } = router.query // $ Source
return (
<>
<div
dangerouslySetInnerHTML={{ __html: id }} // $ Alert
/>
<div
dangerouslySetInnerHTML={{ __html: params.id }} // $ Alert
/>
<div
dangerouslySetInnerHTML={{ __html: params.q }} // $ Alert
/>
</>
)
}
export async function getServerSideProps(context) {
return {
props: {
id: context.params.id || "", // $ Source
q: context.query?.foobar || "", // $ Source
}
}
}