From: Anthony Talarico Date: Thu, 4 Oct 2018 18:48:18 +0000 (-0400) Subject: adding strip slashes to the autocomplete so that fields can be searched with sql... X-Git-Url: http://cvs2.gaslightmedia.com/gitweb/?a=commitdiff_plain;h=ab4f4ef49a6aa4af8bdb4caea4026df5f6d8c906;p=WP-Plugins%2Fglm-member-db.git adding strip slashes to the autocomplete so that fields can be searched with sql concat, in the dashboard widget text search --- diff --git a/models/admin/ajax/glmTextSearch.php b/models/admin/ajax/glmTextSearch.php index f6728732..d9fa9136 100644 --- a/models/admin/ajax/glmTextSearch.php +++ b/models/admin/ajax/glmTextSearch.php @@ -78,6 +78,7 @@ class GlmMembersAdmin_ajax_glmTextSearch $clause = filter_var($_REQUEST['where'], FILTER_SANITIZE_STRING); $searchQuery = filter_var($_REQUEST['query'], FILTER_SANITIZE_STRING); $fields = $_REQUEST['fields']; + $fields = stripslashes($fields); $table = filter_var($_REQUEST['table'], FILTER_SANITIZE_STRING); $sql = "SELECT $fields FROM $table where $clause like '%$searchQuery%'"; $entities = $wpdb->get_results($sql); @@ -92,7 +93,6 @@ class GlmMembersAdmin_ajax_glmTextSearch } $return = array( - "test" => $sql, 'searchData' => $searchData // Where our events list will go );