Files
codeql/javascript/ql/test/query-tests/Security/CWE-079/ReflectedXss/tst3.js
2021-05-18 22:23:27 +02:00

8 lines
193 B
JavaScript

var express = require('express');
var app = express();
app.enable('x-powered-by').disable('x-powered-by').get('/', function (req, res) {
let { p } = req.params;
res.send(p); // NOT OK
});