Files
codeql/javascript/ql/src/Security/CWE-020/ExternalAPITaintStepExample.js
2020-11-19 13:42:25 +00:00

7 lines
158 B
JavaScript

let path = require('path');
express().get('/data', (req, res) => {
let file = path.join(HOME_DIR, 'public', req.query.file);
res.sendFile(file);
});