Skip to content

Commit e7720f7

Browse files
committed
Python/ServerSideRequestForgeryQuery
python/ql/src/Security/CWE-918/PartialServerSideRequestForgery.ql
1 parent 6d8e2b2 commit e7720f7

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

python/ql/lib/semmle/python/security/dataflow/ServerSideRequestForgeryQuery.qll

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,8 @@ private module PartialServerSideRequestForgeryConfig implements DataFlow::Config
6868
predicate observeDiffInformedIncrementalMode() { any() }
6969

7070
Location getASelectedSinkLocation(DataFlow::Node sink) {
71-
// Note: this query does not select the sink itself
71+
result = sink.(Sink).getLocation()
72+
or
7273
result = sink.(Sink).getRequest().getLocation()
7374
}
7475
}

0 commit comments

Comments
 (0)