Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Trusting user input #43

Open
mrshu opened this issue Feb 28, 2018 · 0 comments
Open

Trusting user input #43

mrshu opened this issue Feb 28, 2018 · 0 comments
Labels

Comments

@mrshu
Copy link

mrshu commented Feb 28, 2018

Currently whichever request gets to the /gta endpoint will make it directly into the DB.

This seems to be a security issue where an attacker could basically send the level ID of any level they'd want (with any command they'd want).

@mrshu mrshu added the bug label Feb 28, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant