From 5c9a962b217faa9366027df1920291c80718019f Mon Sep 17 00:00:00 2001 From: Stephen Shkardoon Date: Sun, 24 Mar 2013 23:30:44 +1300 Subject: [PATCH] Uncasted user input cause SQL issues --- code/formfields/FieldEditor.php | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/code/formfields/FieldEditor.php b/code/formfields/FieldEditor.php index 4e30260..e74f833 100755 --- a/code/formfields/FieldEditor.php +++ b/code/formfields/FieldEditor.php @@ -180,7 +180,7 @@ class FieldEditor extends FormField { $parentID = $this->form->getRecord()->ID; if($parentID) { - $parentID = Convert::raw2sql($parentID); + $parentID = (int)$parentID; $sqlQuery = new SQLQuery(); $sqlQuery = $sqlQuery @@ -222,7 +222,7 @@ class FieldEditor extends FormField { // work out the sort by getting the sort of the last field in the form +1 if($parent) { - $sql_parent = Convert::raw2sql($parent); + $sql_parent = (int)$parent; $sqlQuery = new SQLQuery(); $sqlQuery = $sqlQuery