diff --git a/htdocs/ticketsup/class/ticketsup.class.php b/htdocs/ticketsup/class/ticketsup.class.php index b76cb9a0861..34fc63f8366 100644 --- a/htdocs/ticketsup/class/ticketsup.class.php +++ b/htdocs/ticketsup/class/ticketsup.class.php @@ -894,12 +894,12 @@ class Ticketsup extends CommonObject if (!$error) { $sql = "DELETE FROM " . MAIN_DB_PREFIX . "ticketsup_logs"; - $sql .= " WHERE fk_track_id = '" . $this->track_id . "'"; + $sql .= " WHERE fk_track_id = '" . $this->db->escape($this->track_id) . "'"; $resql = $this->db->query($sql); } if (!$error) { $sql = "DELETE FROM " . MAIN_DB_PREFIX . "ticketsup_msg"; - $sql .= " WHERE fk_track_id = '" . $this->track_id . "'"; + $sql .= " WHERE fk_track_id = '" . $this->db->escape($this->track_id) . "'"; $resql = $this->db->query($sql); }