Query parse failure on TM Merge with 'OR' in text

Description

An error occurs when running TM Version merge on a project with the attached source and translation files uploaded

1. Create project version
2. Upload mobydick.txt.pot
3. Select Upload translations for the document, select mobydick.tx.po
4. Create a new version (no copy)
5. Upload mobydick.txt.pot
6. Select TM Version merge from the menu
7. Select the prior version
8. Press merge translations

Environment

None

Activity

Show:
Damian Jansen
May 22, 2018, 6:32 AM

possible sql-injection attack vector? I couldn't craft something to drop tables, but it might just be my lack of skills.

Damian Jansen
May 22, 2018, 6:34 AM

Uploaded a small file that causes the issue.

Ready for Release

Assignee

Sean Flanigan

Reporter

Damian Jansen

Labels

Tested Version/s

None

Components

Fix versions

Affects versions

Priority

High
Configure