Unsanitized user input in HTTP request (SSRF)
Overview
Description
Remediation Guidelines
axios.get(`https://${req.params.host}`); // unsafevar host = "default-api.com"; if (req.params.host === "something-else") { host = "other-api.com"; } axios.get(`https://${host}`);
References
Configuration
Last updated