mirror of
https://github.com/opensourcepos/opensourcepos.git
synced 2026-09-29 22:25:02 -04:00
fix(security): prevent SQL injection in tax controller sort columns
Add sanitizeSortColumn() validation to prevent SQL injection in the sort parameter of search() methods in tax-related controllers. Vulnerable controllers: - Taxes.php: sort column was passed directly to model - Tax_categories.php: sort column was passed directly to model - Tax_codes.php: sort column was passed directly to model - Tax_jurisdictions.php: sort column was passed directly to model Fix: Use sanitizeSortColumn() to validate sort column against allowed headers, defaulting to primary key if invalid.
This commit is contained in:
500 Internal Server Error
Gitea Version: 1.28.0+dev-477-g8b6ad49a5f