laptop and a wrench

Bug

ArcGIS Survey123 sends a poorly constructed query and is logically correct but appears as a potential SQL injection attack on firewalls fixed in version 3.6 but returns in version 3.12.

Last Published: November 23, 2022 ArcGIS Survey123
Bug ID Number BUG-000139808
SubmittedMay 11, 2021
Last ModifiedJune 5, 2024
Applies toArcGIS Survey123
Version found3.12
Operating SystemWindows OS
Operating System VersionN/A
StatusNon-Reproducible

Additional Information

The ArcGIS JavaScript API 3.x version appends AND (1=1) to the WHERE parameter.

Workaround

Disable firewalls or whitelist for ArcGIS Survey123 domains.

Steps to Reproduce

Bug ID: BUG-000139808

Software:

  • ArcGIS Survey123

Get notified when the status of a bug changes

Download the Esri Support App

Discover more on this topic

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options