Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use query parameters in install helper function #1618

Merged
merged 1 commit into from Feb 2, 2020

Commits on Jan 29, 2020

  1. Use query parameters in install helper function

    install_correct_multiselect_custom_fields_db_format() injected actual
    field values in the update SQL queries, which is a potential source for
    SQL injection, and causes the upgrade from MantisBT < 1.2.0 to fail when
    custom_field_table contains an apostrophe.
    
    Fixes #26636
    dregad committed Jan 29, 2020
    Configuration menu
    Copy the full SHA
    f6ef383 View commit details
    Browse the repository at this point in the history