Hi hardik,

Kindly add Html::escape when you save config values to prevent sql injection.

CommentFileSizeAuthor
#6 3104517-6.patch708 byteshardik_patel_12
#4 3104517-2.patch839 byteshardik_patel_12

Comments

ankush_03’s picture

Priority: Normal » Major
hardik_patel_12’s picture

Status: Active » Needs work

Hi @ankushgautam76@gmail.com make sense , will check and do that , otherwise if you have time and you want to submit patch then you can proceed for the same.

hardik_patel_12’s picture

StatusFileSize
new839 bytes

We have to use Html::escape is basically for when page is displaying not when we are storing something, but thanks for pointing issue.

hardik_patel_12’s picture

Status: Needs work » Needs review
hardik_patel_12’s picture

StatusFileSize
new708 bytes

Kindly apply a new patch

hardik_patel_12’s picture

Status: Needs review » Fixed
ankush_03’s picture

Yes it is working !

ankush_03’s picture

It is not mandatory to use Html:: escape is basically for when the page is displaying not when we are storing something. It's good to prevent wherever possible.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.