Files
codeql/javascript/ql/test/query-tests/Security/CWE-094/CodeInjection/webix/webix.js
2025-02-28 13:27:28 +01:00

5 lines
277 B
JavaScript

import * as webix from 'webix';
webix.exec(document.location.hash); // $ Alert[js/code-injection]
webix.ui({ template: document.location.hash }); // $ Alert[js/code-injection]
webix.ui({ template: function () { return document.location.hash } }); // $ Alert[js/code-injection]