Skip to content
This repository has been archived by the owner on Dec 13, 2022. It is now read-only.

Fix: Sanitize and bind host category listing #11774

Merged

Conversation

emabassi-ext
Copy link
Contributor

Description

Queries should be sanitized (if possible) and bound using PDO statement to reduce attack surface and clean legacy code

Where

www/include/configuration/configObject/host_categories/listHostCategories.php

Line: 144

Fixes # MON-14970

Type of change

  • Patch fixing an issue (non-breaking change)
  • New functionality (non-breaking change)
  • Breaking change (patch or feature) that might cause side effects breaking part of the Software

Target serie

  • 21.04.x
  • 21.10.x
  • 22.04.x
  • 22.10.x (master)

How this pull request can be tested ?

Create an host category and link it to host(s) (enabled and disabled) from “Configuration > Hosts > Categories

Check if host category listing is OK: “ Enabled Hosts” and “ Disabled Hosts” columns display correct numbers of hosts

Checklist

Community contributors & Centreon team

  • I have followed the coding style guidelines provided by Centreon
  • I have commented my code, especially new classes, functions or any legacy code modified. (docblock)
  • I have commented my code, especially hard-to-understand areas of the PR.
  • I have rebased my development branch on the base branch (master, maintenance).

@sonarqube-decoration
Copy link

@emabassi-ext emabassi-ext merged commit 43e11dd into develop Sep 19, 2022
@emabassi-ext emabassi-ext deleted the MON-14970-sanitize-and-bind-host-category-listing branch September 19, 2022 08:04
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants