Discovered almost 5 years ago
Source: static code analysis
Category: SQL Injection
Confidence level: Medium

Problem

Possible SQL injection

Location

app/models/post_action.rb:428

Post.where(:id => post_id).update_all(["#{"#{post_action_type_key}_count"} = ?", 1.where(:post_id => post_id).where(:post_action_type_id => post_action_type_id).count])

Category description: SQL injection is when a user is able to manipulate a value which is used unsafely inside a SQL query.

Solution: fix the issue in app/models/post_action.rb or mark it as false positive.