Skip to content

Commit 9add9c7

Browse files
committed
fix: prevenzione sql injection
1 parent 06efa92 commit 9add9c7

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

templates/scadenzario/init.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@
4343
}
4444

4545
if (get('id_anagrafica') && get('id_anagrafica') != 'null') {
46-
$module_query = str_replace('1=1', '1=1 AND `co_scadenziario`.`idanagrafica`="'.get('id_anagrafica').'"', $module_query);
46+
$module_query = str_replace('1=1', '1=1 AND `co_scadenziario`.`idanagrafica`="'.prepare(get('id_anagrafica')).'"', $module_query);
4747
$id_anagrafica = get('id_anagrafica');
4848
}
4949

0 commit comments

Comments
 (0)