Skip to content

[Python]: Improve existing Xpath Injection query #408

@ghost

Description

Query

Relevant PR: github/codeql#6331

Report

This PR improves my earlier Xpath injection query to use APIGraphs.

My earlier ticket #92 was closed sans bounty as the query couldn't get atleast one result then. With the new improvements to the Python tooling and the upgrades to the PR I make now, the earlier undetected vulnerability in andresriancho/django-moth is now detected.

Result(s)

I can confirm that this change leads to atleast one additional detection in andresriancho/django-moth.

Metadata

Metadata

Assignees

No one assigned

    Labels

    All For OneSubmissions to the All for One, One for All bounty

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions