Skip to content
This repository has been archived by the owner on Dec 13, 2022. It is now read-only.

Fix: Sanitize and bind CLAPI Centreon Hostgroup class #11780

Conversation

emabassi-ext
Copy link
Contributor

Description

Queries should be sanitized (if possible) and bound using PDO statement to reduce attack surface and clean legacy code
in
www/class/centreon-clapi/centreonHostGroup.class.php
Lines:

  • 350
  • 355
  • 361

Fixes # MON-14968

Type of change

  • Patch fixing an issue (non-breaking change)
  • New functionality (non-breaking change)
  • Breaking change (patch or feature) that might cause side effects breaking part of the Software

Target serie

  • 21.04.x
  • 21.10.x
  • 22.04.x
  • 22.10.x (master)

How this pull request can be tested ?

Add map icon to an hostgroup

Get map icon image using CLAPI:

centreon -u admin -p 'centreon' -o HG -a getparam -v "test;map_icon_image"
Result should be like (image ID from “Administration > Parameters > Images”):

map_icon_image
5

Checklist

Community contributors & Centreon team

  • I have followed the coding style guidelines provided by Centreon
  • I have commented my code, especially new classes, functions or any legacy code modified. (docblock)
  • I have commented my code, especially hard-to-understand areas of the PR.
  • I have rebased my development branch on the base branch (master, maintenance).

@sonarqube-decoration
Copy link

SonarQube Quality Gate

Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 1 Code Smell

No Coverage information No Coverage information
0.0% 0.0% Duplication

@emabassi-ext emabassi-ext merged commit dbd71ca into develop Sep 19, 2022
@emabassi-ext emabassi-ext deleted the MON-14968-sanitize-and-bind-clapi-centreon-hostgroup-class branch September 19, 2022 08:03
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants