Remove SQL injection "WHERE id='%s'"

Description

https://github.com/folio-org/folio-custom-fields/blob/626b37e/src/main/java/org/folio/repository/CustomFieldsConstants.java#L16 provides

If used it allows for SQL injection attacks. The attacker can use a single quote to gain SQL access.

Solution: Remove.

CSP Request Details

None

CSP Rejection Details

None

Potential Workaround

None

Checklist

hide

Activity

Show:

Details

Assignee

Reporter

Labels

Priority

Development Team

Volaris

RCA Group

Implementation coding issue

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created March 12, 2025 at 9:52 AM
Updated March 12, 2025 at 9:54 AM
TestRail: Cases
TestRail: Runs