4 ms·
... why would you pass $GET through to a logical layer with access to a data store write without sanitizing it? This seems like a pretty basic thing to fix, bu
by blindhippo 3y ago
... why would you pass $GET through to a logical layer with access to a data store write without sanitizing it?
This seems like a pretty basic thing to fix, but then I only have your snippet to go by.
- oefrha 3y agoThat’s a parametrized API that’s supposed to be safe against injection, at least to anyone who’s ever used parametrized APIs and hasn’t read the documentation of this particular library in detail. That it supports wildcard makes as much sense as log4j executing code in textual messages. If an ORM/builder casually puts =/IS and LIKE in the same method, don’t touch it.