Menu

#2 Quotes not properly escaped

open
nobody
None
7
2007-04-26
2007-04-26
costerhout
No

Quotes in the user module are not properly escaped. For example, if a student is input into the database with a ' for the last name, upon display things are messed up. This needs to be checked, as all values taken from the user and put into the database should be escaped.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB