HomeBUGS & ISSUES

Think you found a bug? Report it here.

Test Profile Name - SQL injection Messages in this topic - RSS

Richard.
Richard.
Posts: 4


8/3/2022
Richard.
Richard.
Posts: 4
Hi, just a note to say it appears the 'Test profile name' may expose what looks like a SQL Injection flaw when trying to run a test:


I removed apostrophes - ' - from the 'Test Profile' > 'Test profile name' and ran the test again which appeared to start without error having done that.

HTH,
0 link
George @StresStimulus
George @StresStimulus
Administrator
Posts: 555


8/9/2022
George @StresStimulus
George @StresStimulus
Administrator
Posts: 555
This issue was fixed in v5.6.8255. Thank you for reporting it.


- Cheers
0 link






Copyright © 2024 Stimulus Technology