[wp-trac] [WordPress Trac] #44861: equals sign in WordPress Gutenberg post triggers SQL injection attack on Server

WordPress Trac noreply at wordpress.org
Wed Aug 29 14:08:07 UTC 2018


#44861: equals sign in WordPress Gutenberg post triggers SQL injection attack on
Server
-------------------------------------------------+-------------------------
 Reporter:  jamesfroggatt                        |       Owner:  (none)
     Type:  defect (bug)                         |      Status:  new
 Priority:  normal                               |   Milestone:  Awaiting
                                                 |  Review
Component:  Editor                               |     Version:  4.9.8
 Severity:  normal                               |  Resolution:
 Keywords:  needs-patch needs-screenshots        |     Focuses:
  reporter-feedback close                        |
-------------------------------------------------+-------------------------
Changes (by knutsp):

 * keywords:  needs-patch needs-screenshots good-first-bug => needs-patch
     needs-screenshots reporter-feedback close
 * focuses:  performance =>
 * severity:  critical => normal


Comment:

 Does this happen when using the classic editor, or only when using
 Gutenberg, which is a plugin not maintained on this Trac?

 Either way, probably not a bug in Core or Gutenberg, but a server
 misconfiguration.

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/44861#comment:2>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list