CVE-2026-28781: Craftcms Query Configure Sqli

Mass assignment of user-supplied criteria to a database query object through `Craft::configure()` without unsetting SQL-specific keys allows SQL injection. Attackers can overwrite query properties (like 'where', 'join') to inject arbitrary SQL logic. Ensure you sanitize the criteria array by unsetting unsupported keys (e.g., `where`, `orderBy`) before passin

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-28781-craftcms-query-configure-sqli --engine opengrep

Description

Mass assignment of user-supplied criteria to a database query object through `Craft::configure()` without unsetting SQL-specific keys allows SQL injection. Attackers can overwrite query properties (like 'where', 'join') to inject arbitrary SQL logic. Ensure you sanitize the criteria array by unsetting unsupported keys (e.g., `where`, `orderBy`) before passin