Skip to content

Additional "SQL statements use Python-formatted strings"

High
DogukanUrker published GHSA-7v72-8f83-c6mw Jan 17, 2024

Package

flaskBlog (Python)

Affected versions

Master branch

Patched versions

None

Description

(Opening a new issue because I appear to be unable to comment on issues marked as remediated)

Follow up on #GHSA-66hm-3w7j-jmch with a few more locations containing Python formatting strings:

  • helpers.py#L60
  • login.py#L34
  • changePassword.py#L29
  • deleteComment.py#L19
  • setUserRole.py#L13
  • adminPanelPosts.py#L14
  • adminPanel.py#L13
  • user.py#L24
  • search.py#24
  • deleteUser.py#L19
  • editPost.py#L36
  • adminPanelComments.py#L13
  • dashboard.py#L22
  • adminPanelUsers.py#L13
  • signup.py#L36 (unconfirmed)
  • signup.py#L38 (unconfirmed)
  • deletePost.py#L19
  • post.py#L33

Not all of these are high priority (e.g., post.py#L33 takes an integer value) and there are likely additional throughout the codebase.

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs

Credits