🔒 SQL injection security vulnerabilities https://github.com/siyuan-note/siyuan/issues/13077 https://github.com/siyuan-note/siyuan/issues/13059
This commit is contained in:
parent
7fa1f89061
commit
831d350653
1 changed files with 3 additions and 0 deletions
|
@ -63,6 +63,9 @@ func GetAssetContent(id, query string, queryMethod int) (ret *AssetContent) {
|
|||
query = stringQuery(query)
|
||||
}
|
||||
}
|
||||
if !ast.IsNodeIDPattern(id) {
|
||||
return
|
||||
}
|
||||
|
||||
table := "asset_contents_fts_case_insensitive"
|
||||
filter := " id = '" + id + "'"
|
||||
|
|
Loading…
Add table
Reference in a new issue