agentejo / cockpit

Add content management functionality to any site - plug & play / headless / api-first CMS
http://getcockpit.com
MIT License
5.4k stars 524 forks source link

Fix (MongoLite): change disallowed character from ( to single quote ' #1457

Closed abernh closed 3 years ago

abernh commented 3 years ago

Single quotes would allow to break out of the later formed command string allowing any functions to be executed

rel: https://github.com/agentejo/cockpit/commit/b40d6bdedb87265e700ac09007603e72459e7629#commitcomment-53000630

aheinze commented 3 years ago

Thanks!