Files
codeql/javascript/ql/test/query-tests/Security/CWE-089/tst2.js
2018-08-02 17:53:23 +01:00

13 lines
354 B
JavaScript

var express = require('express');
const sql = require('mssql');
var app = express();
app.get('/post/:id', async function(req, res) {
// OK
sql.query`select * from mytable where id = ${req.params.id}`;
// NOT OK
new sql.Request().query("select * from mytable where id = '" + req.params.id + "'");
});
// semmle-extractor-options: --experimental