-
Type:
Bug
-
Resolution: Fixed
-
Affects Version/s: None
-
Component/s: Editor general
-
High
-
None
-
Fixed unsafe SQL generation when creating task custom fields.
-
None
-
Emptyshow more show less
problem
Task custom field creation builds parts of a schema update from field configuration values. For combobox fields, the default value is not quoted through the database adapter before being used in the generated SQL statement.
solution
Use database adapter quoting for dynamic default values, validate combobox option keys before schema changes, and add regression coverage for values containing quotes or SQL control characters.
Testing
See testinstructions.