DragonTechMC / DTPunishment

Sponge API 5/7 - Punishment and Chat Filter Plugin
http://www.dragontechmc.com/
4 stars 6 forks source link

Fix security issues. #37

Open ryantheleach opened 7 years ago

ryantheleach commented 7 years ago

https://stackoverflow.com/questions/1582161/how-does-a-preparedstatement-avoid-or-prevent-sql-injection

ryantheleach commented 7 years ago

I had some Sponge staff take a look over my changes.

This wasn't actually exploitable yet but I felt like it was close enough that it should be nipped in the butt before someone copies and pastes yet another query and creates one with a variable ban reason, or player name or something.