in workshop/workshop-java-repo-vulnerable/src/main/java/com/handlingformsubmission/GreetingController.java [39:52]
public String Input(HttpServletRequest req, HttpServletResponse resp) throws IOException {
String input = req.getParameter("input");
ScriptEngineManager manager = new ScriptEngineManager();
ScriptEngine engine = manager.getEngineByName("JavaScript");
try {
engine.eval(input);
} catch (ScriptException e) {
return "exception";
}
return null;
//engine.eval(input); // Noncompliant
//return "input";
}