FIX : db escape
This commit is contained in:
parent
a271bb8316
commit
2efea59614
@ -217,7 +217,7 @@ class SkillRank extends CommonObject
|
|||||||
{
|
{
|
||||||
global $langs;
|
global $langs;
|
||||||
|
|
||||||
$sqlfilter = 'fk_object='.$this->fk_object." AND objecttype='".$this->objecttype."' AND fk_skill = ".((int) $this->fk_skill);
|
$sqlfilter = 'fk_object='.$this->fk_object." AND objecttype='".$this->db->escape($this->objecttype)."' AND fk_skill = ".((int) $this->fk_skill);
|
||||||
$alreadyLinked = $this->fetchAll('ASC', 'rowid', 0, 0, array('customsql' => $sqlfilter));
|
$alreadyLinked = $this->fetchAll('ASC', 'rowid', 0, 0, array('customsql' => $sqlfilter));
|
||||||
if (!empty($alreadyLinked)) {
|
if (!empty($alreadyLinked)) {
|
||||||
$this->error = $langs->trans('ErrSkillAlreadyAdded');
|
$this->error = $langs->trans('ErrSkillAlreadyAdded');
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user