Files
codeql/python/ql/test/experimental/query-tests/Security/CWE-074-TemplateInjection/Chameleon.py
2023-08-17 15:45:04 +02:00

11 lines
231 B
Python

from chameleon import PageTemplate
from django.urls import path
from django.http import HttpResponse
def chameleon(request):
template = request.GET['template']
tmpl = PageTemplate(template)
return HttpResponse(tmpl)