case 10 : // it's a customer invoice
case 11 : // it's a customer credit note
case 12 : // it's a customer payment
+ case 13 : // it's a customer dispatch
if (!exists_customer_trans($type, $type_no))
return false;
post_void_customer_trans($type, $type_no);
{
$date = date2sql($date_);
$sql = "INSERT INTO ".TB_PREF."voided (type, id, date_, memo_)
- VALUES ($type, $type_no, '$date', '$memo_')";
+ VALUES ($type, $type_no, ".db_escape($date).", ".db_escape($memo_).")";
db_query($sql, "could not add voided transaction entry");
}