Unsanitized user input in DynamoDB query
Overview
Description
Remediation Guidelines
exports.handler = async function(event, context) { var params = { Key: { "artist": {"S": event.input }, "song": {"S": "Carrot Eton"} }, TableName: "artists" }; var result = await dynamodb.getItem(params).promise() console.log(JSON.stringify(result)) }
References
Configuration
PreviousUnsanitized user input in dynamic HTML insertion (XSS)NextUnsanitized User Input in File Path Traversal
Last updated