Bug 302

Summary: "SQL Injection input in Delivery Note Number is not sanitized/rejected — raw SQL error exposed "
Product: Smartwas Reporter: Karunakaran (Karunakaran)
Component: PurchaseAssignee: Arun (Arun)
Status: OPEN ---    
Severity: Medium    
Priority: ---    
Version: unspecified   
Hardware: PC   
OS: Windows   
Associated Test Case ID: Triaged By: ---
Root Cause Analysis (RCA):
Resolution Summary / Fix Details:
Impact Area:

Description Karunakaran (Karunakaran) 2026-07-09 09:23:52 UTC
"Entering a SQL injection payload in the Delivery Note Number field is not rejected or sanitized by the system. Instead of showing a validation error, the system throws an unhandled SQL error, indicating the input reaches the database layer without sanitization.
"