Replace Function sanitizeInput() with just escapeSql() and update all instances throughout

This commit is contained in:
johnnyq
2026-07-14 17:17:50 -04:00
parent 7bc47a58fe
commit b57ddc0e5c
148 changed files with 1945 additions and 1945 deletions

View File

@@ -20,7 +20,7 @@ enforceUserPermission('module_financial');
// Payment Method Filter
if (isset($_GET['method']) & !empty($_GET['method'])) {
$payment_method_query = "AND (payment_method = '" . sanitizeInput($_GET['method']) . "')";
$payment_method_query = "AND (payment_method = '" . escapeSql($_GET['method']) . "')";
$method_filter = escapeHtml($_GET['method']);
} else {
// Default - any