PaulB
Well-known member
- Affected version
- 2.2.8.0
Replacements it performs:
Will become:
Which MySQL/MariaDB will interpret as a literal backslash followed by a LIKE wildcard.
While this could theoretically result in security vulnerabilities in some add-ons, I can't find any instances in which this would result in a security issue in vanilla XenForo; it just breaks certain searches.
- % -> \%
- _ -> \_
- \ -> \\
Code:
\%
Code:
\\%
While this could theoretically result in security vulnerabilities in some add-ons, I can't find any instances in which this would result in a security issue in vanilla XenForo; it just breaks certain searches.