From ab4f4ef49a6aa4af8bdb4caea4026df5f6d8c906 Mon Sep 17 00:00:00 2001 From: Anthony Talarico Date: Thu, 4 Oct 2018 14:48:18 -0400 Subject: [PATCH] adding strip slashes to the autocomplete so that fields can be searched with sql concat, in the dashboard widget text search --- models/admin/ajax/glmTextSearch.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/models/admin/ajax/glmTextSearch.php b/models/admin/ajax/glmTextSearch.php index f6728732..d9fa9136 100644 --- a/models/admin/ajax/glmTextSearch.php +++ b/models/admin/ajax/glmTextSearch.php @@ -78,6 +78,7 @@ class GlmMembersAdmin_ajax_glmTextSearch $clause = filter_var($_REQUEST['where'], FILTER_SANITIZE_STRING); $searchQuery = filter_var($_REQUEST['query'], FILTER_SANITIZE_STRING); $fields = $_REQUEST['fields']; + $fields = stripslashes($fields); $table = filter_var($_REQUEST['table'], FILTER_SANITIZE_STRING); $sql = "SELECT $fields FROM $table where $clause like '%$searchQuery%'"; $entities = $wpdb->get_results($sql); @@ -92,7 +93,6 @@ class GlmMembersAdmin_ajax_glmTextSearch } $return = array( - "test" => $sql, 'searchData' => $searchData // Where our events list will go ); -- 2.17.1