diff --git a/javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.qhelp b/javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.qhelp index 944801ba3cb..02cbbd0c626 100644 --- a/javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.qhelp +++ b/javascript/ql/src/experimental/Security/CWE-94/ServerSideTemplateInjection.qhelp @@ -15,7 +15,7 @@ run arbitrary code on the application server.

Avoid including user input in any expression or template which may be dynamically rendered. If user input must be included, use context-specific escaping before including it or run -render engine with sandbox options. +the rendering engine with sandbox options.