Skip to content

Conversation

m10x
Copy link
Contributor

@m10x m10x commented Apr 30, 2025

Instead of replacing " with ', "s are now being JSON encoded. Thus it is possible to exploit SQL Injections where " is used for the query string

@BKreisel BKreisel merged commit 9a2a64a into BKreisel:main Apr 30, 2025
@BKreisel
Copy link
Owner

great. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

2 participants