]> git.openstreetmap.org Git - nominatim.git/commit
properly escape class parameter
authorSarah Hoffmann <lonvia@denofr.de>
Sat, 2 May 2020 21:01:27 +0000 (23:01 +0200)
committerSarah Hoffmann <lonvia@denofr.de>
Sat, 2 May 2020 21:01:27 +0000 (23:01 +0200)
commitf549379e318d300e1d7188acdcc16d731b245bf7
treed8edb245c8a91f792d017cff20d184c093e5c954
parent627a487fcfd325f8a340f10298a961d15d2760b6
properly escape class parameter

The class parameter was used as is, allowing for potential
SQL injection via the API.

Thanks to @bladeswords for finding this.
website/details.php