2
0
forked from Wavyzz/dolibarr

Fix escape

This commit is contained in:
Laurent Destailleur
2019-08-27 14:10:23 +02:00
parent 1dccd27b8f
commit 3eb32360ce

View File

@@ -365,7 +365,7 @@ class Commande extends CommonOrder
// Validate
$sql = "UPDATE ".MAIN_DB_PREFIX."commande";
$sql.= " SET ref = '".$num."',";
$sql.= " SET ref = '".$this->db->escape($num)."',";
$sql.= " fk_statut = ".self::STATUS_VALIDATED.",";
$sql.= " date_valid='".$this->db->idate($now)."',";
$sql.= " fk_user_valid = ".$user->id;