Work summary

1: When querying the list, if no user information is passed in, the data of all users will be found out, and there will be security problems.

Special attention should be paid in the process of writing later

2: Similar to the first one, if the query condition is not written in the sql statement (the incoming parameter is not checked), it will also lead to the problem of information leakage

Guess you like

Origin http://10.200.1.11:23101/article/api/json?id=327050092&siteId=291194637