From faefca3cf83c24365dd29cc874024d0cb82732f9 Mon Sep 17 00:00:00 2001 From: "myk%mozilla.org" <> Date: Thu, 8 Nov 2001 08:54:15 +0000 Subject: Fix for bug 108822: Prevent any user from changing their own groupset. Patch by Jake . r=bbaetz,myk --- userprefs.cgi | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'userprefs.cgi') diff --git a/userprefs.cgi b/userprefs.cgi index bd5dcb4f2..bc0f1d672 100755 --- a/userprefs.cgi +++ b/userprefs.cgi @@ -495,8 +495,8 @@ sub SaveFooter { Error("Hmm, the $name query seems to have gone away."); } } - SendSQL("UPDATE profiles SET mybugslink = '" . $::FORM{'mybugslink'} . - "' WHERE userid = $userid"); + SendSQL("UPDATE profiles SET mybugslink = " . SqlQuote($::FORM{'mybugslink'}) . + " WHERE userid = $userid"); } -- cgit v1.2.3-24-g4f1b