SQLi - String Function Managed Rule Preventing Legit File Uploads

Answer these questions to help the Community help you with Security questions.

What is the domain name?
recorder.maricopa.gov

Have you searched for an answer?
Yes - I have looked through the docs and while I understand what the SQLi - String Function managed rule does, I am not finding any reason it is preventing document uploads.

Please share your search results url:
https://dash.cloudflare.com/d77d3cb432e3810b78f77f143e8ff172/recorder.maricopa.gov/security/events?action=managed_challenge&rule-id=63e03eecddfc4b3fb0cad587d32b798c

When you tested your domain, what were the results?

Describe the issue you are having:
Users are attempting to upload files to our server through their accounts. The Filenames are in the format of 495640100SLW03252024-2-1-1–.pdf. Thousands of other users are able to upload documents to this application everyday without getting flagged using the same file format.

This user’s help desk entry:
I’M HAVING TROUBLE UPLOADING DOCUMENTS. I GET LOGGED IN JUST FINE BUT THEN WHEN I TRY TO UPLOAD A DOCUMENT, IT COMES UP AND SAYS IT NEEDS TO VERIFY I AM HUMAN. I CLICK ON THE LITTLE BOX BUT THEN IT JUST TAKES ME RIGHT BACK TO “UPLOAD” AND WHEN I TRY TO UPLOAD IT TAKES ME RIGHT BACK TO THE VERIFICATION PAGE. ANY IDEAS?

What error message or number are you receiving?

What steps have you taken to resolve the issue?

  1. Backed the Managed Ruleset off from BLOCK to Managed Challenge:
  2. Had user rename the file and attempt re-upload DID NOT SOLVE
  3. Had user try different browser and incognito mode DID NOT SOLVE

Was the site working with SSL prior to adding it to Cloudflare?
NA

What are the steps to reproduce the error:

Have you tried from another browser and/or incognito mode?
Yes

Please attach a screenshot of the error:
Similar to this Error:

Hello @shelby.blanton

I see there is a Ticket open under your name for this request as well, and it has been replied to by CSUP.

I will mark this as Closed, as we are actively communicating with you via ticket with account-specific instructions.

1 Like