Skip to content

Docs: Improve clarity in V1.2.4 to prevent ORM-related SQL injection#3202

Draft
ajayojha wants to merge 3 commits intoOWASP:masterfrom
ajayojha:enhance-1.2.4
Draft

Docs: Improve clarity in V1.2.4 to prevent ORM-related SQL injection#3202
ajayojha wants to merge 3 commits intoOWASP:masterfrom
ajayojha:enhance-1.2.4

Conversation

@ajayojha
Copy link

This pull request addresses issue #3201 by clarifying requirement V1.2.4.

This change clarifies the requirement for ORM usage to explicitly mandate allow-list validation for non-parameterizable query parts, preventing a common SQL injection vector OWASP#3201.
@tghosth tghosth marked this pull request as draft June 16, 2025 10:15
@tghosth
Copy link
Collaborator

tghosth commented Jun 16, 2025

Let's discuss in #3201

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants