You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At the moment, the database entries seem not be quoted as far as I understand. So a normal user might use e.g. the search fields to do some SQL injection.
I saw this in when working on PR #12 for #5. Maybe I will find some time for a small PR but I wanted to keep this documented that there is a security vulerability.
The text was updated successfully, but these errors were encountered:
@christianlupus You may be right about that. Luckily, only the findRecipes method should be affected, so a small change to that should take care of it.
I'm no expert on SQL injection myself, so your contribution would be highly appreciated! 🙏
At the moment, the database entries seem not be quoted as far as I understand. So a normal user might use e.g. the search fields to do some SQL injection.
I saw this in when working on PR #12 for #5. Maybe I will find some time for a small PR but I wanted to keep this documented that there is a security vulerability.
The text was updated successfully, but these errors were encountered: