public String Input()

in workshop/workshop-java-repo-vulnerable/src/main/java/com/handlingformsubmission/GreetingController.java [39:52]


  public String Input(HttpServletRequest req, HttpServletResponse resp) throws IOException {
    String input = req.getParameter("input");
    ScriptEngineManager manager = new ScriptEngineManager();
    ScriptEngine engine = manager.getEngineByName("JavaScript");
    try {
     engine.eval(input);
    } catch (ScriptException e) {
     return "exception";
    }
    return null;
    
    //engine.eval(input); // Noncompliant
    //return "input";
  }