const compileTemplate = (name) => {
let sanitized_name = sanitizeReq(name);
let file = fs.readFileSync(""+__dirname+"/"+sanitized_name,"utf-8"); //Taint, assign, pass, template injection
return Handlebars.compile(file);
}
const temp = compileTemplate("file.xml");
##############
欢迎任何意见。谢谢! 车把版本:4.7.7.
尝试对值进行硬编码,清理所有参数。错误仍未解决。