mirror of
https://github.com/Dolibarr/dolibarr.git
synced 2026-02-07 16:41:48 +01:00
Fix escaping
This commit is contained in:
@@ -294,9 +294,9 @@ if (empty($reshook))
|
||||
$sql .= ", targettype";
|
||||
$sql .= ") VALUES (";
|
||||
$sql .= $id_order;
|
||||
$sql .= ", '".$object->origin."'";
|
||||
$sql .= ", '".$db->escape($object->origin)."'";
|
||||
$sql .= ", ".$object->id;
|
||||
$sql .= ", '".$object->element."'";
|
||||
$sql .= ", '".$db->escape($object->element)."'";
|
||||
$sql .= ")";
|
||||
|
||||
if (!$db->query($sql))
|
||||
|
||||
Reference in New Issue
Block a user