Security update merged from 2.1.
[fa-stable.git] / inventory / manage / item_categories.php
index 26a2889fec39035ef5a247f7a5bb377614d3ee8a..233d034b401bf3d361ef49f30621994dc6ab8ebc 100644 (file)
@@ -67,7 +67,7 @@ if ($Mode == 'Delete')
 {
 
        // PREVENT DELETES IF DEPENDENT RECORDS IN 'stock_master'
-       $sql= "SELECT COUNT(*) FROM ".TB_PREF."stock_master WHERE category_id='$selected_id'";
+       $sql= "SELECT COUNT(*) FROM ".TB_PREF."stock_master WHERE category_id=".db_escape($selected_id);
        $result = db_query($sql, "could not query stock master");
        $myrow = db_fetch_row($result);
        if ($myrow[0] > 0)