View date parameter is not cleaned

Created on 10 May 2023, over 1 year ago
Updated 15 May 2023, over 1 year ago

Problem/Motivation

Exception: Failed to parse time string ((select*from(select+sleep(0)union/**/select+1)a)) at position 0 ((): The timezone could not be found in the database in DateTime->__construct() (line 63 of /xxxxxx/web/modules/contrib/date_pager/src/PagerDate.php).

Steps to reproduce

?date=%28select%2Afrom%28select%2Bsleep%280%29union/%2A%2A/select%2B1%29a%29

Proposed resolution

Remaining tasks

User interface changes

API changes

Data model changes

🐛 Bug report
Status

Fixed

Version

2.0

Component

Code

Created by

🇩🇪Germany sleitner

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024