Skip to content

Commit 13c0364

Browse files
authored
Update index.js
1 parent d052293 commit 13c0364

File tree

1 file changed

+1
-15
lines changed

1 file changed

+1
-15
lines changed

routes/index.js

Lines changed: 1 addition & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -357,21 +357,7 @@ exports.about_new = function (req, res, next) {
357357
});
358358
};
359359

360-
/*
361-
// 🚨 NoSQL Injection Vulnerability: Directly using user input as query
362-
exports.vulnerable_nosql_injection = function (req, res, next) {
363-
const query = req.body || {};
364-
365-
// This is dangerous: attacker can send {"$ne": null} to bypass auth
366-
User.findOne(query, function (err, user) {
367-
if (err) return next(err);
368-
if (!user) {
369-
return res.status(404).send("User not found");
370-
}
371-
return res.status(200).send("Welcome " + user.username);
372-
});
373-
};
374-
*/
360+
// Add new Vulnerable code:
375361

376362

377363

0 commit comments

Comments
 (0)