Skip to content

Commit 4e003a8

Browse files
committed
fix: prevenzione sql injection
1 parent 1ab6734 commit 4e003a8

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

modules/anagrafiche/ajax/complete.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@
2525
switch ($resource) {
2626
case 'get_sedi':
2727
$idanagrafica = get('idanagrafica');
28-
$q = "SELECT id, CONCAT_WS( ' - ', nomesede, citta ) AS descrizione FROM an_sedi WHERE idanagrafica='".$idanagrafica."' ".Modules::getAdditionalsQuery(Module::where('name', 'Anagrafiche')->first()->id).' ORDER BY id';
28+
$q = "SELECT id, CONCAT_WS( ' - ', nomesede, citta ) AS descrizione FROM an_sedi WHERE idanagrafica=".prepare($idanagrafica)." ".Modules::getAdditionalsQuery(Module::where('name', 'Anagrafiche')->first()->id).' ORDER BY id';
2929
$rs = $dbo->fetchArray($q);
3030
$n = sizeof($rs);
3131

0 commit comments

Comments
 (0)