Fix sql injection
This commit is contained in:
parent
90c12ae340
commit
07053d8605
@ -320,7 +320,7 @@ if ($search_country) {
|
||||
$sql .= " AND s.fk_pays IN (".$db->sanitize($search_country).')';
|
||||
}
|
||||
if ($search_shipping_method_id > 0) {
|
||||
$sql .= " AND e.fk_shipping_method = ".$search_shipping_method_id;
|
||||
$sql .= " AND e.fk_shipping_method = ".((int) $search_shipping_method_id);
|
||||
}
|
||||
if ($search_tracking) {
|
||||
$sql .= natural_search("e.tracking_number", $search_tracking);
|
||||
|
||||
Loading…
Reference in New Issue
Block a user