Skip to content

Commit

Permalink
Merge pull request #3410 from semgrep/merge-develop-to-release
Browse files Browse the repository at this point in the history
Merge Develop into Release
  • Loading branch information
philipturnbull authored Jun 21, 2024
2 parents 1032ff0 + bc11077 commit f2fff7e
Show file tree
Hide file tree
Showing 2 changed files with 21 additions and 1 deletion.
20 changes: 20 additions & 0 deletions javascript/express/security/injection/tainted-sql-string.js
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,20 @@ app.get('/test4', (req, res) => {
res.send(results)
})

app.get('/test5', (req, res) => {
// ruleid: tainted-sql-string
const query = util.format("UPDATE User SET name = '' WHERE id = '%s'", req.query.message)
const [results, metadata] = await sequelize.query(query);
res.send(results)
})

app.get('/test6', (req, res) => {
// ruleid: tainted-sql-string
const query = util.format("UPDATE %s SET name = '' WHERE id = 0", req.query.table)
const [results, metadata] = await sequelize.query(query);
res.send(results)
})

app.get('/ok', async (req, res) => {
// ok: tainted-sql-string
res.send("message: " + req.query.message);
Expand All @@ -64,4 +78,10 @@ app.post('/ok4', async (req, res) => {
res.send(data);
})

app.post('/ok5', async (req, res) => {
// ok: tainted-sql-string
var data = "This is an update message: " + req.query.message
res.send(data);
})

app.listen(port, () => console.log(`Example app listening at http://localhost:${port}`))
Original file line number Diff line number Diff line change
Expand Up @@ -70,5 +70,5 @@ rules:
`$SQLSTR${$EXPR}...`
- metavariable-regex:
metavariable: $SQLSTR
regex: .*\b(?i)(select|delete|insert|create|update|alter|drop)\b.*
regex: .*\b(?i)(select|delete|insert|create|update\s+.+\sset|alter|drop)\b.*
- focus-metavariable: $EXPR

0 comments on commit f2fff7e

Please sign in to comment.