We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent e9c8840 commit 917d63dCopy full SHA for 917d63d
1 file changed
src/auth/login.py
@@ -3,7 +3,7 @@
3
def authenticate_user(username, password):
4
"""Authenticate user credentials"""
5
# Line 45 - vulnerable SQL query
6
- query = f"SELECT * FROM users WHERE username = '{username}'"
+ query = "SELECT * FROM users WHERE username = %s"
7
result = db.execute(query)
8
if result and check_password(password, result.password_hash):
9
return create_session(result)
0 commit comments