Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0009145Openbravo ERP07. Sales managementpublic2009-05-22 18:142009-06-18 00:00
shuehner 
shuehner 
urgentmajorhave not tried
closedduplicate 
5
pi 
 
Core
No
0009145: SQL injection in Report Invoice Discount
This report has an issue where it is possible to inject code into the executed SQL statement via crafted parameters
No tags attached.
duplicate of defect 0009501 closed shuehner Audit all xsql to ensure that all xsql-parameters of type argument/replace are properly validated -part1 
depends on feature request 0009500 closed shuehner Add infrastructure to VariablesBase class to allow for technical validation of request parameters 
Issue History
2009-05-22 18:14shuehnerNew Issue
2009-05-22 18:14shuehnerAssigned To => rafaroda
2009-05-22 18:16shuehnerNote Added: 0016592
2009-05-25 09:58rafarodaNote Added: 0016601
2009-05-25 09:58rafarodaAssigned Torafaroda => shuehner
2009-05-25 09:58rafarodaStatusnew => scheduled
2009-05-25 09:58rafarodafix_in_branch => pi
2009-06-16 16:33shuehnerRelationship addeddepends on 0009500
2009-06-16 16:40shuehnerRelationship addedblocks 0009501
2009-06-17 18:31shuehnerRelationship replacedduplicate of 0009501
2009-06-17 18:31shuehnerStatusscheduled => closed
2009-06-17 18:31shuehnerNote Added: 0017396
2009-06-17 18:31shuehnerDuplicate ID0 => 9501
2009-06-17 18:31shuehnerResolutionopen => duplicate
2009-06-18 00:00anonymoussf_bug_id0 => 2807995

Notes
(0016592)
shuehner   
2009-05-22 18:16   
likely also be present in 2.40
(0016601)
rafaroda   
2009-05-25 09:58   
Stefan,

Could you please give some steps to reproduce this issue?

Thanks.
(0017396)
shuehner   
2009-06-17 18:31   
First commit into 9501 does include fix for this issue.