Update orm.php

Escape single quotes in the data.
This commit is contained in:
FusionPBX
2016-10-05 09:55:02 -06:00
committed by GitHub
parent cb5228bd0f
commit 73cf433e05

View File

@@ -804,8 +804,8 @@
$sql .= "'".$_SERVER['REMOTE_ADDR']."', ";
//$sql .= "'$transaction_type', ";
$sql .= "now(), ";
$sql .= "'".json_encode($old_array, JSON_PRETTY_PRINT)."', ";
$sql .= "'".json_encode($new_array, JSON_PRETTY_PRINT)."', ";
$sql .= "'".check_str(json_encode($old_array, JSON_PRETTY_PRINT))."', ";
$sql .= "'".check_str(json_encode($new_array, JSON_PRETTY_PRINT))."', ";
$sql .= "'".check_str(json_encode($this->message, JSON_PRETTY_PRINT))."' ";
$sql .= ")";
$this->db->exec(check_sql($sql));