You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If the string " or " (without the quotes, with spaces on both sides) appears in a mail template, when saving, it will get cut out of the template before being saved to the database. This only happens when there are spaces on both sides of the word "or" (not when there is only a space on one side).
Thanks.
The text was updated successfully, but these errors were encountered:
This seems to be related to sanitization of strings before inserting data into the SQL database, in order to prevent code (specifically SQL) injection, but it's known to be a bad implementation of sanitization. Worst, it doesn't works either, as it can be bypassed. See: https://0x4148.com/2016/10/28/a2billing-rce/
Hi A2billing devs,
We are using v2.2.0.
This can be reproduced every time.
If the string " or " (without the quotes, with spaces on both sides) appears in a mail template, when saving, it will get cut out of the template before being saved to the database. This only happens when there are spaces on both sides of the word "or" (not when there is only a space on one side).
Thanks.
The text was updated successfully, but these errors were encountered: