mirror of
https://github.com/github/codeql.git
synced 2026-05-02 20:25:13 +02:00
Add required __raw__ keyword
This __raw__ keyword is required for the actual mongoengine vulnerability. More info can be found below: http://docs.mongoengine.org/guide/querying.html?highlight=inc__#raw-queries
This commit is contained in:
@@ -23,7 +23,7 @@ Movie(title='bb').save()
|
||||
def home_page():
|
||||
unsanitized_search = json.loads(request.args['search'])
|
||||
|
||||
data = Movie.objects(unsanitized_search)
|
||||
data = Movie.objects(__raw__=unsanitized_search)
|
||||
return data.to_json()
|
||||
|
||||
# if __name__ == "__main__":
|
||||
|
||||
@@ -25,7 +25,7 @@ def home_page():
|
||||
unsanitized_search = json.loads(request.args['search'])
|
||||
sanitize(unsanitized_search)
|
||||
|
||||
data = Movie.objects(unsanitized_search)
|
||||
data = Movie.objects(__raw__=unsanitized_search)
|
||||
return data.to_json()
|
||||
|
||||
# if __name__ == "__main__":
|
||||
|
||||
Reference in New Issue
Block a user