2 requêtes de fusion!154Escape all values interpolated in SQL queries in the Perso controller,!151Draft: Escape all values interpolated in SQL queries in the Perso controller
@@ -490,8 +490,11 @@ class Perso extends Controller
publicfunctioncancel($f3,$params)
{
if(!$f3->exists('SESSION.user')){
$f3->reroute('/login');
}
$db=$f3->get('DB');
$result=$db->query("SELECT identifier, user_id from identifiers where identifier like '".$params['id']."'");
$result=$db->query("SELECT identifier, user_id from identifiers where identifier like '".$params['id']."' and user_id='".\Utils::asl($f3->get('SESSION.id'))."'");