Merge pull request #5062 from bafbes/abb-18

fix:missing quote in query in commonobject updatefield function
This commit is contained in:
Laurent Destailleur 2016-04-22 19:51:11 +02:00
commit 284622edbd

View File

@ -4297,7 +4297,7 @@ abstract class CommonObject
}
$this->db->begin();
$sql = "UPDATE ".MAIN_DB_PREFIX.$this->table_element."_extrafields SET $key=".$this->array_options["options_$key"];
$sql = "UPDATE ".MAIN_DB_PREFIX.$this->table_element."_extrafields SET $key='".$this->db->escape($this->array_options["options_$key"])."'";
$sql .= " WHERE fk_object = ".$this->id;
$resql = $this->db->query($sql);
if (! $resql)