mirror of
https://github.com/doctrine/orm.git
synced 2026-03-24 06:52:09 +01:00
DDC-3045: SQL Injection in Persister API #3780
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @doctrinebot on GitHub (Mar 23, 2014).
Originally assigned to: @beberlei on GitHub.
Jira issue originally created by user @beberlei:
Evaluate if its possible to inject SQL through field names when passed to EntityRepository#findBy(), findOneBy() and matching() methods.
@doctrinebot commented on GitHub (Mar 23, 2014):
Comment created by @beberlei:
Not an issue, improved EntityManager unrecognized identifier field error handling.
@doctrinebot commented on GitHub (Mar 23, 2014):
Issue was closed with resolution "Fixed"