Closed (fixed)
Project:
Similar Entries
Version:
7.x-1.x-dev
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
10 Mar 2012 at 01:30 UTC
Updated:
13 Apr 2012 at 05:01 UTC
No filtering done for node title and no parameters assignment used. As a result sql injection is possible through adding node with title containing single quote character. Patch to fix this issue attached.
| Comment | File | Size | Author |
|---|---|---|---|
| 0001-Fix-SQL-injection-issue-through-node-title.patch | 1.36 KB | pavel.karoukin |
Comments
Comment #1
deekayen commentedcommitted
Comment #2
jordojuice commentedAhh just saw this in my email. Thanks for catching this and reporting it. It seems like the security team has been doing some good work judging by all the security fixes in my email.