Skip to content

Trusting user input #43

@mrshu

Description

@mrshu

Currently whichever request gets to the /gta endpoint will make it directly into the DB.

This seems to be a security issue where an attacker could basically send the level ID of any level they'd want (with any command they'd want).

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions