- reflected xss in
index.vuln.js
line16
const Vulnerability = (req, res) => {
var user = req.params.user;
var respond = `
<h1>Hi, ${user}</h1>
`
res.send(respond);
}
- reflected xss in
index.vuln.js
line25
const Vulnerability2 = (req, res) => {
var {user} = req.params;
var respond = `
<script> var x = "${user}" </script>
`
res.send(respond);
}