-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Labels
Description
This doesn't handle values containing special characters correctly, because it doesn't escape them. This is particularly problematic for & and =, since these will now be interpreted as separate parameters. This could lead to security vulnerabilities, similar to SQL-Injection or XSS.
Reactions are currently unavailable