Hacker News new | ask | show | jobs
by marshray 4904 days ago
In the meantime, can you confirm that the disabling of XML and YAML inputs fully mitigates the RCE as well as the SQLi?
2 comments

The vectors for both are the same. The term "SQLI" here is very misleading.
Yes.