Tainted flow: 'url' from requests.post (line 555, network input) → requests.get (network output)
Medium
- Category
- Data Flow
- Content
def _get(self, path, params=None): """GET 请求封装""" url = f'{self.kb_server}{path}' resp = requests.get(url, params=params or {}, headers=self._headers()) return self._parse_response(resp) def _post(self, path, data=None, params=None):- Confidence
- 90% confidence
- Finding
- resp = requests.get(url, params=params or {}, headers=self._headers())
