Skip to content

Entering Date in Invalid DateTime Format Causes Page Error That May Reveal Sensitive Application Information #10

Description

@PhilipRidgers

Version

v2

Severity

Critical

Suggested Priority

High

Observed Behaviour

When entering a value in the 'date from' or 'date to' boxes of the 'Gigs' page, if the value isn't in the correct DateTime format (YYYY-MM-DD) then a page error occurs. The user is sent to an 'InvalidDatetimeFormat' page which contains details about the error, including SQL information. This should be investigated as a matter of urgency, in case any of the data could be used maliciously to access, modify or delete Giga's data and/or functionality.

Expected Behaviour

The user remains on the Gigs page and sees a message asking them to enter a valid date in the correct format.

Reproduction Steps

  1. On 'Gigs' page, enter 2 in the 'date from' field.
  2. Click 'Go'.
Image

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions