Merge pull request #6830 from jfefe/patch-12

Fix #6504: CVE-2017-7886
This commit is contained in:
Laurent Destailleur 2017-05-10 23:41:19 +02:00 committed by GitHub
commit d7b142beb7

View File

@ -439,7 +439,7 @@ class Translate
if (! $found)
{
// Overwrite translation with database read
$sql="SELECT transkey, transvalue FROM ".MAIN_DB_PREFIX."overwrite_trans where lang='".$this->defaultlang."'";
$sql="SELECT transkey, transvalue FROM ".MAIN_DB_PREFIX."overwrite_trans where lang='".$db->escape($this->defaultlang)."'";
$resql=$db->query($sql);
if ($resql)