mirror of
https://github.com/itflow-org/itflow
synced 2026-07-24 09:20:40 +00:00
Replace Function sanitizeInput() with just escapeSql() and update all instances throughout
This commit is contained in:
@@ -20,7 +20,7 @@ enforceUserPermission('module_financial');
|
||||
|
||||
// Payment Method Filter
|
||||
if (isset($_GET['method']) & !empty($_GET['method'])) {
|
||||
$payment_method_query = "AND (payment_method = '" . sanitizeInput($_GET['method']) . "')";
|
||||
$payment_method_query = "AND (payment_method = '" . escapeSql($_GET['method']) . "')";
|
||||
$method_filter = escapeHtml($_GET['method']);
|
||||
} else {
|
||||
// Default - any
|
||||
|
||||
Reference in New Issue
Block a user