Brent 4/10/2019

Unsafe SQL functions in Laravel

Read Original

This technical article details a specific SQL injection vulnerability in Laravel's query builder, related to unsafe functions like `addSelect` and JSON column shorthand. It explains how unescaped user input can be exploited, provides a code example of the attack, and notes the issue was fixed in Laravel 5.8.11. The post serves as a security awareness guide for developers.

Unsafe SQL functions in Laravel

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

1
The Beautiful Web
Jens Oliver Meiert 2 votes
2
Container queries are rad AF!
Chris Ferdinandi 2 votes
4
LLM Use in the Python Source Code
Miguel Grinberg 1 votes
5
Wagon’s algorithm in Python
John D. Cook 1 votes