Skip to:
ColumnFilter.value doesn't escape single quotes.
ColumnFilter.key and OrderingCriterion.key pass double quotes to the database without escaping.
This results in SQL injection.
ColumnFilter.value doesn't escape single quotes.
ColumnFilter.key and OrderingCriterion.key pass double quotes to the database without escaping.
This results in SQL injection.