Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- const express = require('express');
- const app = express()
- const port = 3000
- app.get('/', handleRender)
- function handleRender(req, res) {
- const html = '<div></div>'
- const preloadedState = JSON.stringify({ input: `</script><script>alert(1)</script>` });
- res.send(`
- <!doctype html>
- <html>
- <head>
- <body>
- <div id="root">${html}</div>
- <script>
- window.__PRELOADED_STATE__ = ${preloadedState}
- </script>
- </body>
- </html>
- `);
- }
- app.listen(port)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement