No filtering done for node title and no parameters assignment used. As a result sql injection is possible through adding node with title containing single quote character. Patch to fix this issue attached.

Support from Acquia helps fund testing for Drupal Acquia logo

Comments

deekayen’s picture

Status: Needs review » Fixed

committed

jordojuice’s picture

Ahh just saw this in my email. Thanks for catching this and reporting it. It seems like the security team has been doing some good work judging by all the security fixes in my email.

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.