Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
fifilura
2y ago
0 comments
Share
I have some recollection about filters defined by jinja macros opening up for SQL injections.
0 comments
default
newest
oldest
fifilura
OP
2y ago
And this would be fine if you could lock down arbitrary input in e.g. dropdowns, but it was still possible to input arbitrary strings even in a dropdown because of the choice of widget.
j
/
k
navigate · click thread line to collapse