Quote:
Originally Posted by Daisuke Niwa
Hey! Heads up, I think I found a potential exploit that would allow for SQL Injection with the username. We encountered this error with a member who likes to use apostrophe's in their username:
Luckily the user's name wasn't " justanothermember'; DROP TABLE users; -- " or similar.
Is there any way to sanitize the username input without breaking the entire mod?
|
Fixed in v4.4.0 (attached in first post).
If you still encounter this mysql error, can you pm/email me the page which is causing it, thanks.