forked from hans/Nominatim
The class parameter was used as is, allowing for potential SQL injection via the API. Thanks to @bladeswords for finding this.
The class parameter was used as is, allowing for potential SQL injection via the API. Thanks to @bladeswords for finding this.