[GH-ISSUE #717] SQL injection? #352

Closed
opened 2026-02-25 23:34:01 +03:00 by kerem · 3 comments
Owner

Originally created by @MageSlayer on GitHub (Sep 9, 2023).
Original GitHub issue: https://github.com/go-shiori/shiori/issues/717

Originally assigned to: @fmartingr on GitHub.

Data

  • 1.5.5
  • SQLite(???). I did nothing to setup
  • Devuan x64
  • Web interface

Describe the bug / actual behavior

Entering something like "hea;th" in search control results in "SQL logic error: fts5: syntax error near ";" (1) (500)"

Expected behavior

More qualified error or something sane

To Reproduce

See above

Screenshots

NA

Notes

NA

Originally created by @MageSlayer on GitHub (Sep 9, 2023). Original GitHub issue: https://github.com/go-shiori/shiori/issues/717 Originally assigned to: @fmartingr on GitHub. ## Data - 1.5.5 - SQLite(???). I did nothing to setup - Devuan x64 - Web interface ## Describe the bug / actual behavior Entering something like "hea;th" in search control results in "SQL logic error: fts5: syntax error near ";" (1) (500)" ## Expected behavior More qualified error or something sane ## To Reproduce See above ## Screenshots NA ## Notes NA
Author
Owner

@MageSlayer commented on GitHub (Sep 10, 2023):

Are you sure it's fixed?
I've tested using https://github.com/go-shiori/shiori/actions/runs/5918425180 artifacts.
Still the same error.

<!-- gh-comment-id:1712773397 --> @MageSlayer commented on GitHub (Sep 10, 2023): Are you sure it's fixed? I've tested using https://github.com/go-shiori/shiori/actions/runs/5918425180 artifacts. Still the same error.
Author
Owner

@fmartingr commented on GitHub (Sep 12, 2023):

Can you try again with https://github.com/go-shiori/shiori/releases/tag/v1.6.0-rc.1?

<!-- gh-comment-id:1715065566 --> @fmartingr commented on GitHub (Sep 12, 2023): Can you try again with https://github.com/go-shiori/shiori/releases/tag/v1.6.0-rc.1?
Author
Owner

@MageSlayer commented on GitHub (Sep 12, 2023):

Yes. It's fixed now. Thanks

<!-- gh-comment-id:1715077850 --> @MageSlayer commented on GitHub (Sep 12, 2023): Yes. It's fixed now. Thanks
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/shiori#352
No description provided.