Skip to content

fix(security): close SQL injection in tree sort, TV filters and identifier quoting - #2490

Merged
Seiger merged 5 commits into
evolution-cms:3.5.xfrom
elcreator:fix-key-sql-injections
Oct 7, 2026
Merged

Seiger merged 5 commits into
evolution-cms:3.5.xfrom
elcreator:fix-key-sql-injections

Conversation

@elcreator

Copy link
Copy Markdown

Allowlist the manager tree sort column/direction, escape TV name lists, quote column names and aliases in Database insert/update, and validate TV filter/sort tokens that reach raw SQL. A malformed TV filter now matches nothing instead of being dropped.

elcreator and others added 5 commits October 7, 2026 22:01
…ifier quoting

Allowlist the manager tree sort column/direction, escape TV name lists,
quote column names and aliases in Database insert/update, and validate TV
filter/sort tokens that reach raw SQL. A malformed TV filter now matches
nothing instead of being dropped.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…SE_PATH

Resolve the repository root four levels up and create the assets directory
when another test already defined EVO_BASE_PATH as core/.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…rocess isolation

Pest cannot start RunTestsInSeparateProcesses children, so the scenario
moves to a fixture script that evoRunPhp() launches, like the discovery test.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…ars fields

Limit the number of TV filters (fail closed) and sort terms per call via
SiteContent::MAX_TV_QUERY_TERMS, validate the getTemplateVars field list like
getDocumentChildrenTVars, and drop the redundant length checks and the
duplicate tree sort normalization in the manager ajax endpoint.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@Seiger
Seiger merged commit 5505521 into evolution-cms:3.5.x Oct 7, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants