Skip to content

Conversation

@azurit
Copy link
Member

@azurit azurit commented Dec 1, 2025

For example typo (missing backtick) in SQL query caused FP:

`SELECT `k`.`ac FROM`

Fixes: #37

Copy link
Member

@EsadCetiner EsadCetiner left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change the PR title to something more descriptive before merging?

@azurit azurit changed the title fix: FP fix: FP in SQL query Dec 2, 2025
@azurit
Copy link
Member Author

azurit commented Dec 2, 2025

Done.

@azurit azurit changed the title fix: FP in SQL query fix: FPs in SQL query on multiple places Dec 2, 2025
@azurit
Copy link
Member Author

azurit commented Dec 2, 2025

Will add few more tests soon.

This test is disabled due to unsupported plugin configuration changes.
@azurit azurit requested a review from EsadCetiner December 3, 2025 09:17
ctl:ruleRemoveTargetById=951220;RESPONSE_BODY,\
ctl:ruleRemoveTargetById=953100;RESPONSE_BODY"

SecRule ARGS:route "@streq /preferences/features" \
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you add a short comment to this rule?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Whitelist ARGS err_url and goto from RCE

2 participants