From 892d4f0be3d06eea5a9e1d8bbfcf522dbf4d1d54 Mon Sep 17 00:00:00 2001 From: Aleksandar Karastoyanov Date: Sun, 13 Oct 2024 11:01:52 +0300 Subject: [PATCH] Fix code scanning alert no. 106: Code injection Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- app/routes/user_submit_quest_routes.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/app/routes/user_submit_quest_routes.py b/app/routes/user_submit_quest_routes.py index b34d240e..cacbb542 100644 --- a/app/routes/user_submit_quest_routes.py +++ b/app/routes/user_submit_quest_routes.py @@ -1,4 +1,4 @@ -import random, string, base64 +import random, string, base64, json from datetime import datetime from flask import Blueprint, render_template, redirect, url_for, flash, current_app, request from flask_login import login_required, current_user @@ -242,7 +242,7 @@ def approve_submited_quest(quest_id): @login_required def post_comment(): submited_quest_id = request.form.get('submited_quest_id') - all_comments = eval(request.form.get('submited_quest_comments')) + all_comments = json.loads(request.form.get('submited_quest_comments')) comment = request.form.get('submited_quest_comment') user_id = current_user.user_id user_role = current_user.user_role