matomo-org / matomo

Empowering People Ethically with the leading open source alternative to Google Analytics that gives you full control over your data. Matomo lets you easily collect data from websites & apps and visualise this data and extract insights. Privacy is built-in. Liberating Web Analytics. Star us on Github? +1. And we love Pull Requests!
https://matomo.org/
GNU General Public License v3.0
19.66k stars 2.62k forks source link

Enable MySQL Strict mode as best practise and security improvement #9920

Open mattab opened 8 years ago

mattab commented 8 years ago

The goal of this issue is to enable MySQL strict mode in Piwik.

Why enabling Strict mode?

We would like to bring the best security practises to Piwik and strict mode would be a valuable security improvement.

Requirements

(also refs Require Mysql 5.5 #9107 and making utf8mb4 the collation by default #9785)

Patta commented 4 years ago

+1

tsteur commented 8 months ago

If you can think of a way to exploit this, please report the issue via https://hackerone.com/matomo/ for a bounty.