From 34b1daa65f8167d7b8c362d8cb9519dcd5c3892c Mon Sep 17 00:00:00 2001 From: AulaEmpresaLKS <129507941+AulaEmpresaLKS@users.noreply.github.com> Date: Mon, 31 Mar 2025 11:49:48 +0200 Subject: [PATCH] Update Owner.java Signed-off-by: AulaEmpresaLKS <129507941+AulaEmpresaLKS@users.noreply.github.com> --- .../samples/petclinic/owner/Owner.java | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/src/main/java/org/springframework/samples/petclinic/owner/Owner.java b/src/main/java/org/springframework/samples/petclinic/owner/Owner.java index 675b2140e..d02c9b97c 100644 --- a/src/main/java/org/springframework/samples/petclinic/owner/Owner.java +++ b/src/main/java/org/springframework/samples/petclinic/owner/Owner.java @@ -172,4 +172,18 @@ public class Owner extends Person { pet.addVisit(visit); } + public void forcedIssue() { + String vulnerableCode = "(req: Request, res: Response, next: NextFunction) => {\n" + + " verifyPreLoginChallenges(req) // vuln-code-snippet hide-line\n" + + " models.sequelize.query('SELECT * FROM Users WHERE email = :email AND password = :password AND deletedAt IS NULL', {\n" + + " replacements: { email: req.body.email || '', password: security.hash(req.body.password || '') },\n" + + " model: UserModel,\n" + + " plain: true\n" + + " })\n" + + "}"; + System.out.println(vulnerableCode); + } +} + + }