Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Quotes in tag names break reverse search #6

Open
Vincent-CIRCL opened this issue Jul 1, 2019 · 0 comments
Open

Quotes in tag names break reverse search #6

Vincent-CIRCL opened this issue Jul 1, 2019 · 0 comments

Comments

@Vincent-CIRCL
Copy link

Hi,

I currently use your tool (DataTurks) to classify a private dataset.
We noticed a small issue with the current state of your tool : quotes in tags are breaking the search by tags.

It could imply that your software is not correctly escaping quotes and so is vulnerable to SQLi. This is just a guess, however.

Questions :

  • Are you already aware of this issue ?
  • Do you have a workaround or a fix on a functional side to make the search work with quotes in tags ?
  • If you are aware or if SQLi are confirmed, are you planning to fix the issue on a security side ?

image
image

Thanks for your involvement and your tool. It saving us a lot time.
Have a very nice day

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant