Skip to content

Security issue: Unsanitized DB connection/write #41

@bondjimbond

Description

@bondjimbond

Security issue identified by DGI:

    if (!empty($_POST['data'][strtoupper('Ark_ID')])) { // any pending data must has Ark_ID column
        $noid = Database::dbopen($_GET["db"], dbpath(), DatabaseInterface::DB_WRITE);

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions