Skip to content

Admin lib SQL Injection fixes #228#230

Open
shravan97 wants to merge 1 commit intodelta:masterfrom
shravan97:sql_inj_fix
Open

Admin lib SQL Injection fixes #228#230
shravan97 wants to merge 1 commit intodelta:masterfrom
shravan97:sql_inj_fix

Conversation

@shravan97
Copy link
Member

For the first vulnerability

  • Remove all double quotes if present in the name (this is under the assumption that full names usually don't contain special characters )

For the second vulnerability

  • Explicitly check if $id is a number

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant