Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions app.py
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,8 @@
result = "This message is probably not spam."

# Fetch related spam messages using the input as the WHERE clause
c.execute(f"SELECT message FROM spam_messages WHERE message LIKE '%{message}%'")

Check failure

Code scanning / SonarCloud

Database queries should not be vulnerable to injection attacks High

Change this code to not construct SQL queries directly from user-controlled data. See more on SonarQube Cloud
related_spam_messages = [row[0] for row in c.fetchall()]


# Fetch all spam messages
Expand Down