OakCH / scheduler

Vacation Scheduler for the Oakland Children's Hospital
7 stars 10 forks source link

NurseController possible security risks. #46

Closed helenaut closed 12 years ago

helenaut commented 12 years ago

Risk 1

line 50 event = Event.new(params[:event]) because of mass assignment w/out attr accessible.

Risk 2

potentially malicious - not sure: line 10 @event_strips = Event.event_strips_for_month(@shown_month, :include => :nurse, :conditions => "nurses.unit_id = #{@unit_id} and nurses.shift = '#{@shift}'") UPDATE: rx says potentially malicious; change it to the '?' notation