Vulnerable code: https://npm.runkit.com/getcookies/test/harness.js?t=1525249320108
https://www.npmjs.com/package/express-cookies
1–10 of 18 posts
Vulnerable code: https://npm.runkit.com/getcookies/test/harness.js?t=1525249320108
https://www.npmjs.com/package/express-cookies
No links to git repo in the packages, big warning sign.
No links to git repo in the packages, big warning sign.
Suspiciously good looking profile pic for the developer too; https://www.google.com/search?tbs=sbi:AMhZZite6RvKwDFjIobMX-...
Can someone explain how the injection itself works? I assume it's the require doing the work, but its not so clear how that loads externally instead of from a path in filesystem?
There is no reason to use "express-cookies" when "cookie-parser" exists.