sql-builder icon indicating copy to clipboard operation
sql-builder copied to clipboard

injection ?

Open jonasfrey opened this issue 2 years ago • 0 comments

does this count as injection ?

  var s_value_entered_by_user = '1 OR 1=1';
  var sql = builder
    .table("a_o_user")
    .where("n_id", "=", s_value_entered_by_user)
    // .where("name", "like", "%n%")
    .update({
        s_name: "overwritten!"
    })
    .build();

jonasfrey avatar Feb 20 '23 12:02 jonasfrey