Skip to content

Sqlite code leads to SQL injection vulnerability #128

@matclab

Description

@matclab

See for example

query = "SELECT * FROM %s WHERE %s='%s'" % (

We should instead use parametrized queries.

Metadata

Metadata

Labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions