escape missing in sql request

This commit is contained in:
Faustin 2023-01-22 13:54:39 +01:00
parent 9806941217
commit 4208cb3bc6

View File

@ -123,9 +123,10 @@ if ($action == 'update') {
$oldlabel = preg_replace('/^.*-/', '', $oldname);
$newlabel = preg_replace('/^.*-/', '', $newconstvalue);
$sql = "UPDATE ".MAIN_DB_PREFIX."oauth_token";
$sql.= " SET service = '".$oldprovider."-".$newlabel."'";
$sql.= " WHERE service = '".$oldprovider."-".$oldlabel."'";
$sql.= " SET service = '".$db->escape($oldprovider."-".$newlabel)."'";
$sql.= " WHERE service = '".$db->escape($oldprovider."-".$oldlabel)."'";
$resql = $db->query($sql);