Uploaded image for project: 'Apache Fineract'
  1. Apache Fineract
  2. FINERACT-1338

SQL Injection - While "runreports" api is trying to load report parameters

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Resolved
    • None
    • None
    • None
    • None

    Description

      After solving the error at FINERACT-1336 a new error shows up. 

      while api - runreports
      fineract-provider/api/v1/runreports/OfficeIdSelectOne?parameterType=true
      is spooling the report parameters, user will not see any error on the UI 

      but looking through the console OR postman you see error below

      {     "developerMessage": "The request was invalid. This typically will happen due to validation errors which are provided.",     "httpStatusCode": "400",     "defaultUserMessage": "Unexpected SQL Commands found",     *"userMessageGlobalisationCode": "error.msg.found.sql.injection"* }

      Attachments

        1. image-2021-03-31-15-53-00-571.png
          16 kB
          Francis Guchie
        2. image-2021-04-04-15-56-40-189.png
          117 kB
          Joseph Makara

        Issue Links

          Activity

            People

              francisguchie Francis Guchie
              francisguchie Francis Guchie
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: