File tree Expand file tree Collapse file tree 1 file changed +5
-5
lines changed
javascript/ql/test/query-tests/Security/CWE-918 Expand file tree Collapse file tree 1 file changed +5
-5
lines changed Original file line number Diff line number Diff line change @@ -59,11 +59,11 @@ var server = http.createServer(async function(req, res) {
5959
6060 var client = await CDP ( options ) ;
6161 client . Page . navigate ( { url : tainted } ) ; // $ Alert[js/request-forgery]
62-
62+
6363 CDP ( options ) . catch ( ( ignored ) => { } ) . then ( ( client ) => {
6464 client . Page . navigate ( { url : tainted } ) ; // $ Alert[js/request-forgery]
6565 } )
66-
66+
6767 CDP ( options , ( client ) => {
6868 client . Page . navigate ( { url : tainted } ) ; // $ Alert[js/request-forgery]
6969 } ) ;
@@ -127,15 +127,15 @@ var server2 = http.createServer(function(req, res) {
127127 url : tainted // $ Sink[js/request-forgery]
128128 } ) // $ Alert[js/request-forgery]
129129
130- var myUrl = `${ something } /bla/${ tainted } ` ;
130+ var myUrl = `${ something } /bla/${ tainted } ` ;
131131 axios . get ( myUrl ) ; // $ Alert[js/request-forgery]
132132
133- var myEncodedUrl = `${ something } /bla/${ encodeURIComponent ( tainted ) } ` ;
133+ var myEncodedUrl = `${ something } /bla/${ encodeURIComponent ( tainted ) } ` ;
134134 axios . get ( myEncodedUrl ) ;
135135} )
136136
137137var server2 = http . createServer ( function ( req , res ) {
138- const { URL } = require ( 'url' ) ;
138+ const { URL } = require ( 'url' ) ;
139139 const input = req . query . url ; // $Source[js/request-forgery]
140140 const target = new URL ( input ) ;
141141 axios . get ( target . toString ( ) ) ; // $Alert[js/request-forgery]
You can’t perform that action at this time.
0 commit comments