3 ms·
You might be thinking of an old SQL injection vulnerability that allowed updating models from unchecked request parameters, aka the mass assignment problem[0].
by castwide 7y ago
You might be thinking of an old SQL injection vulnerability that allowed updating models from unchecked request parameters, aka the mass assignment problem[0]. That type of thing can be a concern in any web application, regardless of the framework. Modern Rails does a decent job of discouraging it out of the box.
[0] https://arstechnica.com/information-technology/2012/03/hacker-commandeers-github-to-prove-vuln-in-ruby/ https://arstechnica.com/information-technology/2012/03/hacke...