Skip to content

Commit e2e65ac

Browse files
committed
Add new sink for Android XSS
1 parent b692617 commit e2e65ac

File tree

1 file changed

+2
-1
lines changed
  • java/ql/src/semmle/code/java/security

1 file changed

+2
-1
lines changed

java/ql/src/semmle/code/java/security/XSS.qll

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,8 @@ private class DefaultXssSinkModel extends SinkModelCsv {
3636
[
3737
"javax.servlet.http;HttpServletResponse;false;sendError;(int,String);;Argument[1];xss",
3838
"android.webkit;WebView;false;loadData;;;Argument[0];xss",
39-
"android.webkit;WebView;false;loadDataWithBaseURL;;;Argument[1];xss"
39+
"android.webkit;WebView;false;loadDataWithBaseURL;;;Argument[1];xss",
40+
"android.webkit;WebView;false;evaluateJavascript;;;Argument[0];xss"
4041
]
4142
}
4243
}

0 commit comments

Comments
 (0)