Skip to content

Commit 056566e

Browse files
Update javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql
Co-authored-by: Erik Krogh Kristensen <[email protected]>
1 parent 3a4ea82 commit 056566e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -40,9 +40,9 @@ class SSTIPugSink extends ServerSideTemplateInjectionSink {
4040

4141
class SSTIDotSink extends ServerSideTemplateInjectionSink {
4242
SSTIDotSink() {
43-
exists(CallNode compile, Node sink |
43+
exists(CallNode compile |
4444
compile = moduleImport("dot").getAMemberCall("template") and
45-
sink.getStartLine() != sink.getASuccessor().getStartLine() and
45+
exists(compile.getACall()) and
4646
this = compile.getArgument(0)
4747
)
4848
}

0 commit comments

Comments
 (0)