SQL injektionn

This commit is contained in:
2000-Trek 2023-06-14 22:15:05 +02:00
parent 36da985835
commit d108bca11d

View file

@ -112,7 +112,7 @@ def remove_user():
@app.route("/adduser/user", methods=['GET']) @app.route("/adduser/user", methods=['GET'])
def adduser(): def adduser():
user = request.args.get("username") user = request.args.get("username")
c.execute(f"SELECT * FROM users WHERE username='{str(user)}'") c.execute(f"SELECT * FROM users WHERE username='%users'", {'user' : user})
if c.fetchall() == []: if c.fetchall() == []:
c.execute("INSERT or IGNORE INTO users (username, balance) VALUES ('%(user)s', 0)", {'user' : user} ) c.execute("INSERT or IGNORE INTO users (username, balance) VALUES ('%(user)s', 0)", {'user' : user} )
conn.commit() conn.commit()