unimailrocks / unimail

unimail makes world domination happen
0 stars 0 forks source link

Escape all user-input to Mongo #74

Open rivertam opened 7 years ago

rivertam commented 7 years ago

We're actually currently vulnerable to this. Use something like mongo-object-escape.