cxronen / OpenRoom

Other
0 stars 0 forks source link

CX SQL_Injection @ or-authenticate.php [master] #86

Open cxronen opened 4 years ago

cxronen commented 4 years ago

SQL_Injection issue exists @ or-authenticate.php in branch master

Method <?php at line 1 of or-authenticate.php gets user input from the _POST element. This element’s value then flows through the code without being properly sanitized or validated, and is eventually used in a database query in method <?php at line 1 of or-authenticate.php. This may enable an SQL Injection attack.

Severity: High

CWE:89

Checkmarx

Lines: 103


Code (Line #103):

$username = isset($_POST["username"])?$_POST["username"]:"";

cxronen commented 4 years ago

Issue still exists.

cxronen commented 4 years ago

Issue still exists.

cxronen commented 4 years ago

Issue still exists.

cxronen commented 4 years ago

Issue still exists.

cxronen commented 4 years ago

Issue still exists.

cxronen commented 4 years ago

Issue still exists.

cxronen commented 4 years ago

Issue still exists.

cxronen commented 4 years ago

Issue still exists.