Skip to content

Add database utilities with security vulnerabilities#2

Open
lsvishaal wants to merge 1 commit intomasterfrom
feature/security-issues
Open

Add database utilities with security vulnerabilities#2
lsvishaal wants to merge 1 commit intomasterfrom
feature/security-issues

Conversation

@lsvishaal
Copy link
Owner

Demo PR with SQL injection and hardcoded credentials for testing

- SQL Injection: Direct string interpolation in SQL query
- Hardcoded Credentials: Admin username/password in code
- Plain Text API Key Storage: No encryption for sensitive data
- SSRF Risk: No URL validation in external API calls
- DoS Risk: No timeout on HTTP requests
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant