Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/DomBasedXss/express.js
2025-02-28 13:27:28 +01:00

11 lines
283 B
JavaScript

var express = require('express');
var app = express();
import { JSDOM } from "jsdom";
app.get('/some/path', function (req, res) {
new JSDOM(req.param("wobble"), { runScripts: "dangerously" }); // $ Alert
new JSDOM(req.param("wobble"), { runScripts: "outside-only" });
});