MDL-15184: fix sql injection vulnerability
This commit is contained in:
@@ -377,10 +377,14 @@ function hotpot_delete_selected_attempts(&$hotpot, $del) {
|
||||
$select = "hotpot='$hotpot->id' AND status=".HOTPOT_STATUS_ABANDONED;
|
||||
break;
|
||||
case 'selection':
|
||||
$ids = (array)data_submitted();
|
||||
unset($ids['del']);
|
||||
unset($ids['id']);
|
||||
if (!empty($ids)) {
|
||||
$ids = array();
|
||||
$data = (array)data_submitted();
|
||||
foreach ($data as $name => $value) {
|
||||
if (preg_match('/^box\d+$/', $name)) {
|
||||
$ids[] = intval($value);
|
||||
}
|
||||
}
|
||||
if (count($ids)) {
|
||||
$select = "hotpot='$hotpot->id' AND clickreportid IN (".implode(',', $ids).")";
|
||||
}
|
||||
break;
|
||||
|
||||
Reference in New Issue
Block a user