# the app is using a serializer and we were sent a blob of JSON, they could # have come from that JSON, and thus could be hashrefs (JSON SQL injection) # - for database providers, feeding a c