Brent 4/10/2019

Unsafe SQL functions in Laravel

Read Original

This technical article details a specific SQL injection vulnerability in Laravel's query builder, related to unsafe functions like `addSelect` and JSON column shorthand. It explains how unescaped user input can be exploited, provides a code example of the attack, and notes the issue was fixed in Laravel 5.8.11. The post serves as a security awareness guide for developers.

Unsafe SQL functions in Laravel

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser