DevNoam / WarrantyTrack

📊🏪 WarrantyTrack - Track your customers inquiries
http://api.noamsapir.me/Experiments/WarrantyTrack
1 stars 1 forks source link

Security breach #10

Closed DevNoam closed 3 weeks ago

DevNoam commented 1 year ago

The pages search.php and caseinspect.php. Are potential to sql inject vulnerability.

Need to limit the search to letters only and if the case haven't found, redirect to 404 page.

This has a high risk for WAN versions of the tool.