Module RemotePropertyInjection

Provides a taint tracking configuration for reasoning about injections in property names, used either for writing into a property, into a header or for calling an object’s method.

Import path

semmle.javascript.security.dataflow.RemotePropertyInjection

Imports

Express

Provides classes for working with Express applications.

PropertyInjectionShared

Provides predicates for reasoning about flow of user-controlled values that are used as property names.

javascript

Provides classes for working with JavaScript programs, as well as JSON, YAML and HTML.

Modules