Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-5532

Getting server error :save admin user with Single quote In USER id

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Platform
    • Labels:
      None
    • Module:
      BenAdmin
    • Reported by:
      Harbinger
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Good To Have

      Description

      Getting Server error: Admin User page
      1]add User ID:Single quote:
      2]Click on save button
      3]Getting Server error
      Refer attached screen shots:
      below is error Log:

      ErrorID : 0
      ErrorSource : ControllerAppTier.GetData->WORKTERRAControllerAppTier.GetData->AdminUser.GetData->AdminUser.GetAdminUserForGivenName->CommonBusinessRoutines.GetSingleValue
      ErrorMessage: Incorrect syntax near 'Donald'.
      Unclosed quotation mark after the character string ' AND Users.SystemUserID = SystemUsers.ID '.
      StackTrace: at WORKTERRA.Shared.WORKTERRAControllerAppTier.GetData(WORKTERRAControllerWebTierEntity objWORKTERRAControllerWebTierEntity)
      at WORKTERRA.ControllerAppTier.GetData(Int32 intProjectsId, String strInput)
      TargetSite: System.String GetData(WORKTERRA.Shared.WORKTERRAControllerWebTierEntity)

        Attachments

          Activity

          rashmita.dudhe Rashmita Dudhe (Inactive) created issue -
          rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
          Field Original Value New Value
          Assignee Vijay Siddha [ vijays ] Vijayendra Shinde [ ID10506 ]
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Hi Rashmita Dudhe,

          When we enter single quote in username, while checking if that user already exists in system or not, it was throwing an error during query execution.

          We have fixed this issue. Code has been checked in into LB.

          Prasad Pise,
          Can we try sql injection on this username input of Partner/Broker page and Admin page?

          Thanks.
          CC: Samir, Vijay Siddha, Rakesh Roy, Satya

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Hi Rashmita Dudhe , When we enter single quote in username, while checking if that user already exists in system or not, it was throwing an error during query execution. We have fixed this issue. Code has been checked in into LB. Prasad Pise , Can we try sql injection on this username input of Partner/Broker page and Admin page? Thanks. CC: Samir , Vijay Siddha , Rakesh Roy , Satya
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Status Open [ 1 ] In Development [ 10007 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Code Reviewed By Saurabh Sablaka [ 11909 ]
          Component/s Platform [ 10006 ]
          Dev Due Date 19/Oct/2016
          Developer Vijayendra Shinde [ ID10506 ]
          Issue Importance Good To Have [ 11802 ]
          Item State Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209)
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Assignee Vijayendra Shinde [ ID10506 ] Rashmita Dudhe [ rashmita.dudhe ]
          khandu.kshirsagar Khandu Kshirsagar (Inactive) made changes -
          Item State Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
          Hide
          rashmita.dudhe Rashmita Dudhe (Inactive) added a comment -

          Verified on Lb Environment.
          For admin user with Single quote In USER id is successfully saved.
          also check by login to the system.
          working fine

          Show
          rashmita.dudhe Rashmita Dudhe (Inactive) added a comment - Verified on Lb Environment. For admin user with Single quote In USER id is successfully saved. also check by login to the system. working fine
          rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
          Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
          rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
          Status In Development [ 10007 ] Local Testing [ 10200 ]
          khandu.kshirsagar Khandu Kshirsagar (Inactive) made changes -
          Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602)
          Hide
          rashmita.dudhe Rashmita Dudhe (Inactive) added a comment -

          Verified on Stage Environment.
          For admin user with Single quote In USER id is successfully saved.
          also check by login to the system.
          working fine

          Show
          rashmita.dudhe Rashmita Dudhe (Inactive) added a comment - Verified on Stage Environment. For admin user with Single quote In USER id is successfully saved. also check by login to the system. working fine
          rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217)
          rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
          Status Local Testing [ 10200 ] Stage Testing [ 10201 ]
          ashwin.wankhede Ashwin Wankhede (Inactive) made changes -
          Item State Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
          rakeshr Rakesh Roy (Inactive) made changes -
          Issue Category EBS [ 10350 ] Harbinger [ 10700 ]
          rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
          Attachment Alecto_Critical_ill.png [ 31304 ]
          Hide
          vijayendra Vijayendra Shinde (Inactive) added a comment -

          Hi Rashmita Dudhe,

          I guess you attached some different JIRA ticket image in this ticket.

          Please confirm.

          CC: Samir, Vijay Siddha, Rakesh Roy

          Show
          vijayendra Vijayendra Shinde (Inactive) added a comment - Hi Rashmita Dudhe , I guess you attached some different JIRA ticket image in this ticket. Please confirm. CC: Samir , Vijay Siddha , Rakesh Roy
          rakeshr Rakesh Roy (Inactive) made changes -
          Status Stage Testing [ 10201 ] Production Testing [ 10202 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Resolution Fixed [ 1 ]
          Status Production Testing [ 10202 ] Production Complete [ 10028 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Production Complete(10222)Level 1 values: Closed(10223)
          rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
          Status Production Complete [ 10028 ] Closed [ 6 ]
          Transition Time In Source Status Execution Times
          Vijayendra Shinde (Inactive) made transition -
          Open In Development
          8h 26m 1
          Rashmita Dudhe (Inactive) made transition -
          In Development In LB Testing
          12h 30m 1
          Rashmita Dudhe (Inactive) made transition -
          In LB Testing Stage Testing
          6d 23h 55m 1
          Rakesh Roy (Inactive) made transition -
          Stage Testing In Production Testing
          9d 10h 22m 1
          Rakesh Roy (Inactive) made transition -
          In Production Testing Production Complete
          3d 1h 51m 1
          Rashmita Dudhe (Inactive) made transition -
          Production Complete Closed
          136d 11h 8m 1

            People

            Assignee:
            rashmita.dudhe Rashmita Dudhe (Inactive)
            Reporter:
            rashmita.dudhe Rashmita Dudhe (Inactive)
            Developer:
            Vijayendra Shinde (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Dev Due Date: