diff --git a/htdocs/asset/class/asset.class.php b/htdocs/asset/class/asset.class.php index 7727fe24f93..19c15839231 100644 --- a/htdocs/asset/class/asset.class.php +++ b/htdocs/asset/class/asset.class.php @@ -839,7 +839,7 @@ class Asset extends CommonObject } $sql = "DELETE FROM " . MAIN_DB_PREFIX . "asset_depreciation"; $sql .= " WHERE fk_asset = " . (int) $this->id; - $sql .= " AND depreciation_mode NOT IN ('" . implode("', '", $modes) . "')"; + $sql .= " AND depreciation_mode NOT IN ('" . $this->db->sanitize(implode("', '", $modes)) . "')"; $resql = $this->db->query($sql); if (!$resql) {