Security sql statements update against sql injection attacks.
[fa-stable.git] / sales / customer_payments.php
index 8a391032279e0576228bf0b8cccad697438ab4e4..92e44b505e2cac9750e66d2b06d8ab36c70a0a70 100644 (file)
@@ -162,7 +162,7 @@ function read_customer_data()
                ".TB_PREF."credit_status.dissallow_invoices
                FROM ".TB_PREF."debtors_master, ".TB_PREF."credit_status
                WHERE ".TB_PREF."debtors_master.credit_status = ".TB_PREF."credit_status.id
-                       AND ".TB_PREF."debtors_master.debtor_no = '" . $_POST['customer_id'] . "'";
+                       AND ".TB_PREF."debtors_master.debtor_no = ".db_escape($_POST['customer_id']);
 
        $result = db_query($sql, "could not query customers");