#28680: Document that Func's.__init__()'s **extra and as_sql()'s **extra_context
aren't escaped
------------------------------------------------+------------------------
Reporter: Hynek Cernoch | Owner: nobody
Type: Cleanup/optimization | Status: new
Component: Documentation | Version: 1.11
Severity: Normal | Keywords:
Triage Stage: Accepted | Has patch: 0
Needs documentation: 0 | Needs tests: 0
Patch needs improvement: 0 | Easy pickings: 0
UI/UX: 0 |
------------------------------------------------+------------------------
I found an SQL injection possibility due to unclear documentation about
query expression:
`class Func(*expressions, **extra)`
if unsafe user input is passed by keyword parameters `extra` it is
unprotected, while positional parameters are protected by compile and
passing through sql execute parameters, never merged to SQL by % format.
{{{
class Position(Func):
function = 'POSITION'
template = "%(function)s('%(substring)s' in %(expressions)s)"
def __init__(self, expression, substring):
super(Position, self).__init__(expression, substring=substring)
}}}
--
Ticket URL: <https://code.djangoproject.com/ticket/28680>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/051.bca24e5d24f5442f0a843840375065a1%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.