|
224 | 224 | | tst.js:484:33:484:63 | decodeU ... n.hash) | tst.js:484:43:484:62 | window.location.hash | tst.js:484:33:484:63 | decodeU ... n.hash) | Cross-site scripting vulnerability due to $@. | tst.js:484:43:484:62 | window.location.hash | user-provided value | |
225 | 225 | | tst.js:492:18:492:54 | target. ... "), '') | tst.js:491:16:491:39 | documen ... .search | tst.js:492:18:492:54 | target. ... "), '') | Cross-site scripting vulnerability due to $@. | tst.js:491:16:491:39 | documen ... .search | user-provided value | |
226 | 226 | | typeahead.js:25:18:25:20 | val | typeahead.js:20:22:20:45 | documen ... .search | typeahead.js:25:18:25:20 | val | Cross-site scripting vulnerability due to $@. | typeahead.js:20:22:20:45 | documen ... .search | user-provided value | |
| 227 | +| v-html.vue:2:8:2:23 | v-html=tainted | v-html.vue:6:42:6:58 | document.location | v-html.vue:2:8:2:23 | v-html=tainted | Cross-site scripting vulnerability due to $@. | v-html.vue:6:42:6:58 | document.location | user-provided value | |
227 | 228 | | various-concat-obfuscations.js:4:4:4:31 | "<div>" ... </div>" | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | various-concat-obfuscations.js:4:4:4:31 | "<div>" ... </div>" | Cross-site scripting vulnerability due to $@. | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | user-provided value | |
228 | 229 | | various-concat-obfuscations.js:5:4:5:26 | `<div>$ ... </div>` | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | various-concat-obfuscations.js:5:4:5:26 | `<div>$ ... </div>` | Cross-site scripting vulnerability due to $@. | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | user-provided value | |
229 | 230 | | various-concat-obfuscations.js:6:4:6:43 | "<div>" ... /div>") | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | various-concat-obfuscations.js:6:4:6:43 | "<div>" ... /div>") | Cross-site scripting vulnerability due to $@. | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | user-provided value | |
@@ -748,6 +749,7 @@ edges |
748 | 749 | | typeahead.js:20:22:20:45 | documen ... .search | typeahead.js:20:13:20:45 | target | provenance | | |
749 | 750 | | typeahead.js:21:12:21:17 | target | typeahead.js:24:30:24:32 | val | provenance | | |
750 | 751 | | typeahead.js:24:30:24:32 | val | typeahead.js:25:18:25:20 | val | provenance | | |
| 752 | +| v-html.vue:6:42:6:58 | document.location | v-html.vue:2:8:2:23 | v-html=tainted | provenance | | |
751 | 753 | | various-concat-obfuscations.js:2:6:2:39 | tainted | various-concat-obfuscations.js:4:14:4:20 | tainted | provenance | | |
752 | 754 | | various-concat-obfuscations.js:2:6:2:39 | tainted | various-concat-obfuscations.js:5:12:5:18 | tainted | provenance | | |
753 | 755 | | various-concat-obfuscations.js:2:6:2:39 | tainted | various-concat-obfuscations.js:6:19:6:25 | tainted | provenance | | |
@@ -1400,6 +1402,8 @@ nodes |
1400 | 1402 | | typeahead.js:21:12:21:17 | target | semmle.label | target | |
1401 | 1403 | | typeahead.js:24:30:24:32 | val | semmle.label | val | |
1402 | 1404 | | typeahead.js:25:18:25:20 | val | semmle.label | val | |
| 1405 | +| v-html.vue:2:8:2:23 | v-html=tainted | semmle.label | v-html=tainted | |
| 1406 | +| v-html.vue:6:42:6:58 | document.location | semmle.label | document.location | |
1403 | 1407 | | various-concat-obfuscations.js:2:6:2:39 | tainted | semmle.label | tainted | |
1404 | 1408 | | various-concat-obfuscations.js:2:16:2:39 | documen ... .search | semmle.label | documen ... .search | |
1405 | 1409 | | various-concat-obfuscations.js:4:4:4:31 | "<div>" ... </div>" | semmle.label | "<div>" ... </div>" | |
|
0 commit comments