Skip to content

Commit 3a01067

Browse files
authored
Add NoSQL sinks and update message
1 parent 9dcb110 commit 3a01067

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

javascript/src/audit/CWE-089/SqlInjectionAudit.ql

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,5 +17,5 @@ import semmle.javascript.security.dataflow.SqlInjectionQuery as SqlInjection
1717
import semmle.javascript.security.dataflow.NosqlInjectionQuery as NosqlInjection
1818

1919
from DataFlow::Node sink
20-
where sink instanceof SqlInjection::Sink
21-
select sink, "Command Injection sink"
20+
where sink instanceof SqlInjection::Sink or sink instanceof NosqlInjection::Sink
21+
select sink, "Possible SQL Injection sink"

0 commit comments

Comments
 (0)