WhisperX tag archive

#owasp-cwe-89

This page collects WhisperX intelligence signals tagged #owasp-cwe-89. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-22 18:27:32 · GitHub Issues

1. SQL Injection Vulnerability in Flask Routes Exposes Student Database Search

A high-severity SQL injection vulnerability has been identified in the application's search functionality, allowing attacker-controlled input to be concatenated directly into database queries. The flaw resides in `app/routes.py` at line 34, where user-provided search parameters from the 'q' query string are embedded in...