added escaping for db query in method for getting zone

This commit is contained in:
KMityai 2023-07-07 15:58:04 +03:00
parent 62605b11ed
commit f5f55dd449

View File

@ -124,6 +124,7 @@ class DataRepository extends \retailcrm\Base {
* @return array * @return array
*/ */
public function getZoneByName($name) { public function getZoneByName($name) {
$name = $this->db->escape($name);
$query = $this->db->query("SELECT * FROM `" . DB_PREFIX . "zone` WHERE name = '" . $name . "'"); $query = $this->db->query("SELECT * FROM `" . DB_PREFIX . "zone` WHERE name = '" . $name . "'");
return $query->row; return $query->row;