- Joined
- May 4, 2023
Those are prepared queries, not concatenated. They are probably not vulnerable if XenForo is escaping these properly.It also has raw SQL queries:
Methods ought to be type-hinted but may not be feasible. XenForo doesn't publish method prototypes for XF2, only general concept advice and could be invariant.
I skimmed through these when it was first published and the commit messages would have me storming over to my junior devs' desks for a friendly autism calming session but it's 99% CRUD operations and closed dependency injection operations. For all the hubbub it's pretty mundane service glue.
